CVE-2014-1571

Bugzilla < 4.0.15, 4.1.x-4.2.x < 4.2.11, 4.3.x-4.4.x < 4.4.6, 4.5.x < 4.5.6 - Sensitive Info Exposure

Title source: llm
STIX 2.1

Description

Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 allows remote authenticated users to obtain sensitive private-comment information by leveraging a role as a flag recipient, related to Bug.pm, Flag.pm, and a mail template.

References (9)

Core 9
Core References
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2014:200
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2014-November/142524.html
Third Party Advisory x_refsource_confirm
http://advisories.mageia.org/MGASA-2014-0412.html
Vendor Advisory x_refsource_confirm
http://www.bugzilla.org/security/4.0.14/
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2014-October/141309.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2014-October/141321.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1030978

Scores

EPSS 0.0050
EPSS Percentile 66.4%

Details

CWE
CWE-200
Status published
Products (45)
fedoraproject/fedora 19
fedoraproject/fedora 20
fedoraproject/fedora 21
mozilla/bugzilla 2.0
mozilla/bugzilla 2.2
mozilla/bugzilla 2.4
mozilla/bugzilla 2.6
mozilla/bugzilla 2.8
mozilla/bugzilla 2.9
mozilla/bugzilla 2.10
... and 35 more
Published Oct 13, 2014
Tracked Since Feb 18, 2026