PT-2004-2539 · Mozilla · Bugzilla

Casey Klein

·

Published

2004-10-25

·

Updated

2017-07-11

·

CVE-2004-1633

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Bugzilla versions 2.9 through 2.18rc2 Bugzilla version 2.19 from CVS
Description The issue allows remote authenticated users to modify the keywords in a bug. This is due to the process bug.cgi script not checking edit permissions on the keywords field. The modification can be done via the keywordaction parameter.
Recommendations For Bugzilla versions 2.9 through 2.18rc2, restrict access to the process bug.cgi script until a fix is available. For Bugzilla version 2.19 from CVS, avoid using the keywordaction parameter in the process bug.cgi script until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1633

Affected Products

Bugzilla