PT-2014-4217 · Mozilla · Bugzilla
Published
2014-04-20
·
Updated
2016-04-04
·
CVE-2014-1517
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Bugzilla versions 2.x through 4.4.2
Bugzilla versions 4.5.x prior to 4.5.3
Description
The issue is related to a "login CSRF" problem where the login form does not properly handle a correctly authenticated but unintended login attempt. This makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account and then submit a vulnerability report.
Recommendations
For Bugzilla versions 2.x through 4.4.2, update to version 4.4.3 or later.
For Bugzilla versions 4.5.x prior to 4.5.3, update to version 4.5.3 or later.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bugzilla