CVE Vulnerabilities

CVE-2001-1407

Published: Sep 10, 2001 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Bugzilla before 2.14 allows Bugzilla users to bypass group security checks by marking a bug as the duplicate of a restricted bug, which adds the user to the CC list of the restricted bug and allows the user to view the bug.

Affected Software

NameVendorStart VersionEnd Version
BugzillaMozilla2.4 (including)2.4 (including)
BugzillaMozilla2.6 (including)2.6 (including)
BugzillaMozilla2.8 (including)2.8 (including)
BugzillaMozilla2.10 (including)2.10 (including)
BugzillaMozilla2.12 (including)2.12 (including)
BugzillaMozilla2.14 (including)2.14 (including)
Red Hat Powertools 7.0RedHat*
Red Hat Powertools 7.1RedHat*

References