First published: Thu Jan 31 2002(Updated: )
show_bug.cgi in Bugzilla before 2.14.1 allows a user with "Bugs Access" privileges to see other products that are not accessible to the user, by submitting a bug and reading the resulting Product pulldown menu.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Bugzilla | <=2.14.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0009 has been classified as a moderate severity vulnerability due to its ability to expose sensitive product information to unauthorized users.
To fix CVE-2002-0009, upgrade Bugzilla to version 2.14.1 or later to ensure access controls are properly enforced.
Users with 'Bugs Access' privileges in Bugzilla versions prior to 2.14.1 are impacted by CVE-2002-0009.
CVE-2002-0009 is an access control vulnerability that allows unauthorized access to product information.
CVE-2002-0009 was reported in January 2002 as a security issue in Bugzilla.