First published: Mon Sep 10 2001(Updated: )
Bugzilla before 2.14 does not properly restrict access to confidential bugs, which could allow Bugzilla users to bypass viewing permissions via modified bug id parameters in (1) process_bug.cgi, (2) show_activity.cgi, (3) showvotes.cgi, (4) showdependencytree.cgi, (5) showdependencygraph.cgi, (6) showattachment.cgi, or (7) describecomponents.cgi.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Bugzilla | =2.10 | |
Mozilla Bugzilla | =2.6 | |
Mozilla Bugzilla | =2.4 | |
Mozilla Bugzilla | =2.12 | |
Mozilla Bugzilla | =2.8 | |
Mozilla Bugzilla | =2.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1401 is classified as a moderate severity vulnerability due to its ability to expose confidential bug information.
To fix CVE-2001-1401, upgrade Bugzilla to version 2.14 or later.
CVE-2001-1401 is an access control vulnerability that allows users to bypass viewing permissions for confidential bugs.
CVE-2001-1401 affects Bugzilla versions 2.10 through 2.14.
The components involved in CVE-2001-1401 include process_bug.cgi, show_activity.cgi, showvotes.cgi, and others where the bug ID parameter can be manipulated.