Bugzilla 2.17.5 through 2.17.7 embeds the password in an image URL, which could allow local users to view the password in the web server log files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bugzilla | Mozilla | 2.4 (including) | 2.4 (including) |
Bugzilla | Mozilla | 2.6 (including) | 2.6 (including) |
Bugzilla | Mozilla | 2.8 (including) | 2.8 (including) |
Bugzilla | Mozilla | 2.10 (including) | 2.10 (including) |
Bugzilla | Mozilla | 2.12 (including) | 2.12 (including) |
Bugzilla | Mozilla | 2.14 (including) | 2.14 (including) |
Bugzilla | Mozilla | 2.14.1 (including) | 2.14.1 (including) |
Bugzilla | Mozilla | 2.14.2 (including) | 2.14.2 (including) |
Bugzilla | Mozilla | 2.14.3 (including) | 2.14.3 (including) |
Bugzilla | Mozilla | 2.14.4 (including) | 2.14.4 (including) |
Bugzilla | Mozilla | 2.14.5 (including) | 2.14.5 (including) |
Bugzilla | Mozilla | 2.16 (including) | 2.16 (including) |
Bugzilla | Mozilla | 2.16.1 (including) | 2.16.1 (including) |
Bugzilla | Mozilla | 2.16.2 (including) | 2.16.2 (including) |
Bugzilla | Mozilla | 2.16.3 (including) | 2.16.3 (including) |
Bugzilla | Mozilla | 2.16.4 (including) | 2.16.4 (including) |
Bugzilla | Mozilla | 2.16.5 (including) | 2.16.5 (including) |
Bugzilla | Mozilla | 2.17 (including) | 2.17 (including) |
Bugzilla | Mozilla | 2.17.1 (including) | 2.17.1 (including) |
Bugzilla | Mozilla | 2.17.3 (including) | 2.17.3 (including) |
Bugzilla | Mozilla | 2.17.4 (including) | 2.17.4 (including) |
Bugzilla | Mozilla | 2.17.5 (including) | 2.17.5 (including) |
Bugzilla | Mozilla | 2.17.6 (including) | 2.17.6 (including) |
Bugzilla | Mozilla | 2.17.7 (including) | 2.17.7 (including) |