Search.pm in Bugzilla 2.19.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 allows remote attackers to determine the group memberships of arbitrary users via vectors involving the Search interface, boolean charts, and group-based pronouns.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:17
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.fedoraproject.org/pipermail/package-announce/2010-August/046518.html - | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2010-August/046534.html - | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2010-August/046546.html - | |
References | () http://secunia.com/advisories/40892 - Vendor Advisory | |
References | () http://secunia.com/advisories/41128 - | |
References | () http://www.bugzilla.org/security/3.2.7/ - | |
References | () http://www.securityfocus.com/bid/42275 - | |
References | () http://www.vupen.com/english/advisories/2010/2035 - | |
References | () http://www.vupen.com/english/advisories/2010/2205 - | |
References | () https://bugzilla.mozilla.org/show_bug.cgi?id=417048 - | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=623423 - |
Information
Published : 2010-08-16 15:14
Updated : 2024-11-21 01:17
NVD link : CVE-2010-2756
Mitre link : CVE-2010-2756
CVE.ORG link : CVE-2010-2756
JSON object : View
Products Affected
mozilla
- bugzilla
CWE
CWE-264
Permissions, Privileges, and Access Controls