Bugzilla before 2.14 includes the username and password in URLs, which could allow attackers to gain privileges by reading the information from the web server logs, or by shoulder-surfing and observing the web browsers location bar.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bugzilla | Mozilla | 2.4 (including) | 2.4 (including) |
Bugzilla | Mozilla | 2.6 (including) | 2.6 (including) |
Bugzilla | Mozilla | 2.8 (including) | 2.8 (including) |
Bugzilla | Mozilla | 2.10 (including) | 2.10 (including) |
Bugzilla | Mozilla | 2.12 (including) | 2.12 (including) |
Bugzilla | Mozilla | 2.14 (including) | 2.14 (including) |
Red Hat Powertools 7.0 | RedHat | * | |
Red Hat Powertools 7.1 | RedHat | * |