CVE-2002-0009: Medium severity Bugzilla vulnerability
showbug.cgi in Bugzilla before 2.14.1 allows a user with "Bugs Access" privileges to see other products that are not accessible to the user, by submitting a bug and reading the resulting Product pulldown menu.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0009?
CVE-2002-0009 has been classified as a moderate severity vulnerability due to its ability to expose sensitive product information to unauthorized users.
How do I fix CVE-2002-0009?
To fix CVE-2002-0009, upgrade Bugzilla to version 2.14.1 or later to ensure access controls are properly enforced.
Who is impacted by CVE-2002-0009?
Users with 'Bugs Access' privileges in Bugzilla versions prior to 2.14.1 are impacted by CVE-2002-0009.
What type of vulnerability is CVE-2002-0009?
CVE-2002-0009 is an access control vulnerability that allows unauthorized access to product information.
When was CVE-2002-0009 reported?
CVE-2002-0009 was reported in January 2002 as a security issue in Bugzilla.