CVE-2001-1401

Bugzilla < 2.14 - Unauthenticated Confidential Bug Access via Modified Bug ID Parameters

Title source: llm
STIX 2.1

Description

Bugzilla before 2.14 does not properly restrict access to confidential bugs, which could allow Bugzilla users to bypass viewing permissions via modified bug id parameters in (1) process_bug.cgi, (2) show_activity.cgi, (3) showvotes.cgi, (4) showdependencytree.cgi, (5) showdependencygraph.cgi, (6) showattachment.cgi, or (7) describecomponents.cgi.

References (9)

Core 9
Core References
Patch, Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2001-107.html
Issue Tracking x_refsource_confirm
http://bugzilla.mozilla.org/show_bug.cgi?id=39531
Issue Tracking x_refsource_confirm
http://bugzilla.mozilla.org/show_bug.cgi?id=82781
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=99912899900567
Issue Tracking x_refsource_confirm
http://bugzilla.mozilla.org/show_bug.cgi?id=70189
Issue Tracking x_refsource_confirm
http://bugzilla.mozilla.org/show_bug.cgi?id=39533
Issue Tracking x_refsource_confirm
http://bugzilla.mozilla.org/show_bug.cgi?id=39526
Issue Tracking x_refsource_confirm
http://bugzilla.mozilla.org/show_bug.cgi?id=39527
Issue Tracking x_refsource_confirm
http://bugzilla.mozilla.org/show_bug.cgi?id=39524

Scores

EPSS 0.0167
EPSS Percentile 74.3%

Details

Status published
Products (6)
mozilla/bugzilla 2.4
mozilla/bugzilla 2.6
mozilla/bugzilla 2.8
mozilla/bugzilla 2.10
mozilla/bugzilla 2.12
mozilla/bugzilla 2.14
Published Sep 10, 2001
Tracked Since Feb 18, 2026