CVE-2001-1401: High severity Bugzilla vulnerability
Bugzilla before 2.14 does not properly restrict access to confidential bugs, which could allow Bugzilla users to bypass viewing permissions via modified bug id parameters in (1) processbug.cgi, (2) showactivity.cgi, (3) showvotes.cgi, (4) showdependencytree.cgi, (5) showdependencygraph.cgi, (6) showattachment.cgi, or (7) describecomponents.cgi.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2001-1401?
CVE-2001-1401 is classified as a moderate severity vulnerability due to its ability to expose confidential bug information.
How do I fix CVE-2001-1401?
To fix CVE-2001-1401, upgrade Bugzilla to version 2.14 or later.
What type of vulnerability is CVE-2001-1401?
CVE-2001-1401 is an access control vulnerability that allows users to bypass viewing permissions for confidential bugs.
Which versions of Bugzilla are affected by CVE-2001-1401?
CVE-2001-1401 affects Bugzilla versions 2.10 through 2.14.
What components of Bugzilla are involved in CVE-2001-1401?
The components involved in CVE-2001-1401 include process_bug.cgi, show_activity.cgi, showvotes.cgi, and others where the bug ID parameter can be manipulated.