CVE Vulnerabilities

CVE-2012-0465

Published: Apr 27, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Bugzilla 3.5.x and 3.6.x before 3.6.9, 3.7.x and 4.0.x before 4.0.6, and 4.1.x and 4.2.x before 4.2.1, when the inbound_proxies option is enabled, does not properly validate the X-Forwarded-For HTTP header, which allows remote attackers to bypass the lockout policy via a series of authentication requests with (1) different IP address strings in this header or (2) a long string in this header.

Affected Software

NameVendorStart VersionEnd Version
BugzillaMozilla3.5.1 (including)3.5.1 (including)
BugzillaMozilla3.5.2 (including)3.5.2 (including)
BugzillaMozilla3.5.3 (including)3.5.3 (including)
BugzillaMozilla3.6.0 (including)3.6.0 (including)
BugzillaMozilla3.6.1 (including)3.6.1 (including)
BugzillaMozilla3.6.2 (including)3.6.2 (including)
BugzillaMozilla3.6.3 (including)3.6.3 (including)
BugzillaMozilla3.6.4 (including)3.6.4 (including)
BugzillaMozilla3.6.5 (including)3.6.5 (including)
BugzillaMozilla3.6.6 (including)3.6.6 (including)
BugzillaMozilla3.6.7 (including)3.6.7 (including)
BugzillaMozilla3.6.8 (including)3.6.8 (including)
BugzillaMozilla3.7.1 (including)3.7.1 (including)
BugzillaMozilla3.7.2 (including)3.7.2 (including)
BugzillaMozilla3.7.3 (including)3.7.3 (including)
BugzillaMozilla4.0.1 (including)4.0.1 (including)
BugzillaMozilla4.0.2 (including)4.0.2 (including)
BugzillaMozilla4.0.3 (including)4.0.3 (including)
BugzillaMozilla4.0.4 (including)4.0.4 (including)
BugzillaMozilla4.0.5 (including)4.0.5 (including)
BugzillaMozilla4.1.1 (including)4.1.1 (including)
BugzillaMozilla4.1.2 (including)4.1.2 (including)
BugzillaMozilla4.1.3 (including)4.1.3 (including)
BugzillaMozilla4.2 (including)4.2 (including)
BugzillaMozilla4.2-rc1 (including)4.2-rc1 (including)
BugzillaMozilla4.2-rc2 (including)4.2-rc2 (including)
BugzillaUbuntuhardy*
BugzillaUbuntulucid*
BugzillaUbuntunatty*
BugzillaUbuntuoneiric*
BugzillaUbuntuupstream*

References