PT-2005-3962 · Mozilla · Bugzilla
Frédéric Buclin
·
Published
2005-10-05
·
Updated
2017-07-11
·
CVE-2005-3138
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Bugzilla versions 2.18rc1 through 2.18.3
Bugzilla versions 2.19 through 2.20rc2
Bugzilla version 2.21
Description
The issue allows remote attackers to obtain sensitive information, such as the list of installed products, via the
config.cgi file. This file remains accessible even when the requirelogin parameter is set.Recommendations
For Bugzilla versions 2.18rc1 through 2.18.3, restrict access to the
config.cgi file to minimize the risk of exploitation.
For Bugzilla versions 2.19 through 2.20rc2, consider disabling the config.cgi file until a fix is available.
For Bugzilla version 2.21, avoid using the requirelogin parameter in a way that relies on it to secure the config.cgi file until the issue is resolved.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bugzilla