CVE-2001-1407: High severity Bugzilla vulnerability
Published Sep 10, 2001
·Updated
Bugzilla before 2.14 allows Bugzilla users to bypass group security checks by marking a bug as the duplicate of a restricted bug, which adds the user to the CC list of the restricted bug and allows the user to view the bug.
Affected Software
6 affected components
Bugzilla=2.10
Bugzilla=2.6
Bugzilla=2.4
Bugzilla=2.12
Bugzilla=2.8
Bugzilla=2.14
Remediation
Patch Available
Event History
Sep 10, 2001
CVE Published
04:00 AM
Apr 2, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1407?
CVE-2001-1407 has been classified as a moderate severity vulnerability.
2
How do I fix CVE-2001-1407?
To fix CVE-2001-1407, upgrade Bugzilla to version 2.14 or later.
3
What versions of Bugzilla are affected by CVE-2001-1407?
CVE-2001-1407 affects Bugzilla versions 2.10, 2.4, 2.6, 2.8, and 2.12.
4
What risk does CVE-2001-1407 pose to Bugzilla users?
CVE-2001-1407 allows unauthorized users to view restricted bugs by exploiting a security oversight.
5
Can CVE-2001-1407 impact data confidentiality?
Yes, CVE-2001-1407 may compromise data confidentiality by allowing access to sensitive information in restricted bugs.