CVE Vulnerabilities

CVE-2003-1046

Published: Aug 18, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

describecomponents.cgi in Bugzilla 2.17.3 and 2.17.4 does not properly verify group membership when bug entry groups are used, which allows remote attackers to list component descriptions for otherwise restricted products.

Affected Software

NameVendorStart VersionEnd Version
BugzillaMozilla2.4 (including)2.4 (including)
BugzillaMozilla2.6 (including)2.6 (including)
BugzillaMozilla2.8 (including)2.8 (including)
BugzillaMozilla2.10 (including)2.10 (including)
BugzillaMozilla2.12 (including)2.12 (including)
BugzillaMozilla2.14 (including)2.14 (including)
BugzillaMozilla2.14.1 (including)2.14.1 (including)
BugzillaMozilla2.14.2 (including)2.14.2 (including)
BugzillaMozilla2.14.3 (including)2.14.3 (including)
BugzillaMozilla2.14.4 (including)2.14.4 (including)
BugzillaMozilla2.14.5 (including)2.14.5 (including)
BugzillaMozilla2.16 (including)2.16 (including)
BugzillaMozilla2.16.1 (including)2.16.1 (including)
BugzillaMozilla2.16.2 (including)2.16.2 (including)
BugzillaMozilla2.16.3 (including)2.16.3 (including)
BugzillaMozilla2.17.1 (including)2.17.1 (including)
BugzillaMozilla2.17.3 (including)2.17.3 (including)
BugzillaMozilla2.17.4 (including)2.17.4 (including)

References