Bugzilla 2.17.1 through 2.18, 2.19.1, and 2.19.2, when a user is prompted to log in while attempting to view a chart, displays the password in the URL, which may allow local users to gain sensitive information from web logs or browser history.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bugzilla | Mozilla | 2.10 (including) | 2.10 (including) |
Bugzilla | Mozilla | 2.12 (including) | 2.12 (including) |
Bugzilla | Mozilla | 2.14 (including) | 2.14 (including) |
Bugzilla | Mozilla | 2.14.1 (including) | 2.14.1 (including) |
Bugzilla | Mozilla | 2.14.2 (including) | 2.14.2 (including) |
Bugzilla | Mozilla | 2.14.3 (including) | 2.14.3 (including) |
Bugzilla | Mozilla | 2.14.4 (including) | 2.14.4 (including) |
Bugzilla | Mozilla | 2.14.5 (including) | 2.14.5 (including) |
Bugzilla | Mozilla | 2.16 (including) | 2.16 (including) |
Bugzilla | Mozilla | 2.16.1 (including) | 2.16.1 (including) |
Bugzilla | Mozilla | 2.16.2 (including) | 2.16.2 (including) |
Bugzilla | Mozilla | 2.16.3 (including) | 2.16.3 (including) |
Bugzilla | Mozilla | 2.16.4 (including) | 2.16.4 (including) |
Bugzilla | Mozilla | 2.16.5 (including) | 2.16.5 (including) |
Bugzilla | Mozilla | 2.17 (including) | 2.17 (including) |
Bugzilla | Mozilla | 2.17.1 (including) | 2.17.1 (including) |
Bugzilla | Mozilla | 2.17.3 (including) | 2.17.3 (including) |
Bugzilla | Mozilla | 2.17.4 (including) | 2.17.4 (including) |
Bugzilla | Mozilla | 2.17.5 (including) | 2.17.5 (including) |
Bugzilla | Mozilla | 2.17.6 (including) | 2.17.6 (including) |
Bugzilla | Mozilla | 2.17.7 (including) | 2.17.7 (including) |
Bugzilla | Mozilla | 2.18-rc1 (including) | 2.18-rc1 (including) |
Bugzilla | Mozilla | 2.18-rc2 (including) | 2.18-rc2 (including) |
Bugzilla | Mozilla | 2.19.1 (including) | 2.19.1 (including) |
Bugzilla | Mozilla | 2.19.2 (including) | 2.19.2 (including) |