Bugzilla 2.19.3 through 2.20 does not properly handle // sequences in URLs when redirecting a user from the login form, which could cause it to generate a partial URL in a form action that causes the users browser to send the form data to another domain.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bugzilla | Mozilla | 2.19.3 (including) | 2.19.3 (including) |
Bugzilla | Mozilla | 2.20 (including) | 2.20 (including) |
Bugzilla | Mozilla | 2.20-rc1 (including) | 2.20-rc1 (including) |
Bugzilla | Mozilla | 2.20-rc2 (including) | 2.20-rc2 (including) |
Bugzilla | Mozilla | 2.21 (including) | 2.21 (including) |
Bugzilla | Mozilla | 2.21.1 (including) | 2.21.1 (including) |
Bugzilla | Mozilla | 2.21.2 (including) | 2.21.2 (including) |
Bugzilla | Ubuntu | dapper | * |
Bugzilla | Ubuntu | upstream | * |