CVE-2003-1046

Bugzilla 2.17.3-2.17.4 - Unauthenticated Information Disclosure via describecomponents.cgi

Title source: llm
STIX 2.1

Description

describecomponents.cgi in Bugzilla 2.17.3 and 2.17.4 does not properly verify group membership when bug entry groups are used, which allows remote attackers to list component descriptions for otherwise restricted products.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/343185
Issue Tracking x_refsource_confirm
http://bugzilla.mozilla.org/show_bug.cgi?id=209742
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/8953
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/13602

Scores

EPSS 0.0135
EPSS Percentile 68.4%

Details

Status published
Products (18)
mozilla/bugzilla 2.4
mozilla/bugzilla 2.6
mozilla/bugzilla 2.8
mozilla/bugzilla 2.10
mozilla/bugzilla 2.12
mozilla/bugzilla 2.14
mozilla/bugzilla 2.14.1
mozilla/bugzilla 2.14.2
mozilla/bugzilla 2.14.3
mozilla/bugzilla 2.14.4
... and 8 more
Published Aug 18, 2004
Tracked Since Feb 18, 2026