CVE Vulnerabilities

CVE-2005-3139

Published: Oct 05, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Bugzilla 2.19.1 through 2.20rc2 and 2.21, with user matching turned on in substring mode, allows attackers to list all users whose names match an arbitrary substring, even when the usevisibilitygroups parameter is set.

Affected Software

NameVendorStart VersionEnd Version
BugzillaMozilla2.19.1 (including)2.19.1 (including)
BugzillaMozilla2.19.2 (including)2.19.2 (including)
BugzillaMozilla2.19.3 (including)2.19.3 (including)
BugzillaMozilla2.20-rc1 (including)2.20-rc1 (including)
BugzillaMozilla2.20-rc2 (including)2.20-rc2 (including)
BugzillaMozilla2.21 (including)2.21 (including)
BugzillaUbuntuupstream*

References