CVE Vulnerabilities

CVE-2001-1407

Published: Sep 10, 2001 | Modified: Oct 18, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Bugzilla before 2.14 allows Bugzilla users to bypass group security checks by marking a bug as the duplicate of a restricted bug, which adds the user to the CC list of the restricted bug and allows the user to view the bug.

Affected Software

Name Vendor Start Version End Version
Bugzilla Mozilla 2.4 (including) 2.4 (including)
Bugzilla Mozilla 2.6 (including) 2.6 (including)
Bugzilla Mozilla 2.8 (including) 2.8 (including)
Bugzilla Mozilla 2.10 (including) 2.10 (including)
Bugzilla Mozilla 2.12 (including) 2.12 (including)
Bugzilla Mozilla 2.14 (including) 2.14 (including)

References