PT-2014-4217 · Mozilla · Bugzilla

Published

2014-04-20

·

Updated

2016-04-04

·

CVE-2014-1517

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Bugzilla versions 2.x through 4.4.2 Bugzilla versions 4.5.x prior to 4.5.3
Description The issue is related to a "login CSRF" problem where the login form does not properly handle a correctly authenticated but unintended login attempt. This makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account and then submit a vulnerability report.
Recommendations For Bugzilla versions 2.x through 4.4.2, update to version 4.4.3 or later. For Bugzilla versions 4.5.x prior to 4.5.3, update to version 4.5.3 or later.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-1517
MGASA-2014-0199
MGASA-2014-0200

Affected Products

Bugzilla