CVE-2004-0702: Medium severity Bugzilla vulnerability
DBI in Bugzilla 2.17.1 through 2.17.7 displays the database password in an error message when the SQL server is not running, which could allow remote attackers to gain sensitive information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0702?
CVE-2004-0702 is considered a medium severity vulnerability due to its potential for exposing sensitive database information.
How do I fix CVE-2004-0702?
To fix CVE-2004-0702, upgrade to a patched version of Bugzilla that is not vulnerable to this issue.
Which versions of Bugzilla are affected by CVE-2004-0702?
CVE-2004-0702 affects Bugzilla versions 2.17.1 through 2.17.7, as well as several earlier versions.
What type of information is exposed by CVE-2004-0702?
CVE-2004-0702 can expose the database password in error messages if the SQL server is not running.
Are there any workarounds for CVE-2004-0702?
A possible workaround for CVE-2004-0702 is to configure error handling to prevent sensitive information from being displayed in error messages.