CVE Vulnerabilities

CVE-2007-4539

Published: Aug 27, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The WebService (XML-RPC) interface in Bugzilla 2.23.3 through 3.0.0 does not enforce permissions for the time-tracking fields of bugs, which allows remote attackers to obtain sensitive information via certain XML-RPC requests, as demonstrated by the (1) Deadline and (2) Estimated Time fields.

Affected Software

NameVendorStart VersionEnd Version
BugzillaMozilla2.4 (including)2.4 (including)
BugzillaMozilla2.6 (including)2.6 (including)
BugzillaMozilla2.8 (including)2.8 (including)
BugzillaMozilla2.9 (including)2.9 (including)
BugzillaMozilla2.23.3 (including)2.23.3 (including)
BugzillaMozilla2.23.4 (including)2.23.4 (including)
BugzillaMozilla3.0.0 (including)3.0.0 (including)

References