Vulnerability Name: | CCN-51600 | ||||||
Published: | 2009-07-08 | ||||||
Updated: | 2009-07-08 | ||||||
Summary: | Bugzilla could allow a remote attacker to bypass security restrictions, caused by improper access restrictions on reporters without canconfirm privileges. An attacker could exploit this vulnerability to confirm bugs or set the status of the bug. | ||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||
CVSS v2 Severity: | 4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||
Vulnerability Consequences: | Bypass Security | ||||||
References: | Source: CCN Type: SA35739 Bugzilla "canconfirm" Security Bypass Vulnerability Source: CCN Type: Bugzilla Web site 3.3.4 and 3.2.3 Security Advisory Source: CCN Type: OSVDB ID: 55754 Bugzilla canconfirm Arbitrary Bug Status Manipulation Source: CCN Type: BID-35604 Bugzilla Bug Status Modification Security Bypass Vulnerability Source: CCN Type: Bugzilla@Mozilla Bug 495257 [SECURITY] Reporters without canconfirm privileges can confirm their own bugs Source: XF Type: UNKNOWN bugzilla-canconfirm-security-bypass(51600) | ||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
BACK |