CVE-2001-1401
Bugzilla < 2.14 - Unauthenticated Confidential Bug Access via Modified Bug ID Parameters
Title source: llmDescription
Bugzilla before 2.14 does not properly restrict access to confidential bugs, which could allow Bugzilla users to bypass viewing permissions via modified bug id parameters in (1) process_bug.cgi, (2) show_activity.cgi, (3) showvotes.cgi, (4) showdependencytree.cgi, (5) showdependencygraph.cgi, (6) showattachment.cgi, or (7) describecomponents.cgi.
References (9)
Core 9
Core References
Patch, Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2001-107.html
Issue Tracking x_refsource_confirm
http://bugzilla.mozilla.org/show_bug.cgi?id=39531
Issue Tracking x_refsource_confirm
http://bugzilla.mozilla.org/show_bug.cgi?id=82781
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=99912899900567
Issue Tracking x_refsource_confirm
http://bugzilla.mozilla.org/show_bug.cgi?id=70189
Issue Tracking x_refsource_confirm
http://bugzilla.mozilla.org/show_bug.cgi?id=39533
Issue Tracking x_refsource_confirm
http://bugzilla.mozilla.org/show_bug.cgi?id=39526
Issue Tracking x_refsource_confirm
http://bugzilla.mozilla.org/show_bug.cgi?id=39527
Issue Tracking x_refsource_confirm
http://bugzilla.mozilla.org/show_bug.cgi?id=39524
Scores
EPSS
0.0167
EPSS Percentile
74.3%
Details
Status
published
Products (6)
mozilla/bugzilla
2.4
mozilla/bugzilla
2.6
mozilla/bugzilla
2.8
mozilla/bugzilla
2.10
mozilla/bugzilla
2.12
mozilla/bugzilla
2.14
Published
Sep 10, 2001
Tracked Since
Feb 18, 2026