CVE-2004-0703: High severity Bugzilla vulnerability
Published Jul 21, 2004
·Updated
Unknown vulnerability in the administrative controls in Bugzilla 2.17.1 through 2.17.7 allows users with "grant membership" privileges to grant memberships to groups that the user does not control.
Affected Software
24 affected components
Bugzilla=2.17.6
Bugzilla=2.16.1
Bugzilla=2.16.2
Bugzilla=2.17.4
Bugzilla=2.10
Bugzilla=2.17.1
Bugzilla=2.16
Bugzilla=2.14.2
Bugzilla=2.14.3
Bugzilla=2.14.4
Bugzilla=2.6
Bugzilla=2.17.5
Bugzilla=2.17.3
Bugzilla=2.4
Bugzilla=2.16.4
Bugzilla=2.12
Bugzilla=2.8
Bugzilla=2.16.3
Bugzilla=2.14.5
Bugzilla=2.17.7
Bugzilla=2.17
Bugzilla=2.14.1
Bugzilla=2.16.5
Bugzilla=2.14
Remediation
Patch Available
Event History
Jul 21, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0703?
CVE-2004-0703 is considered a moderate severity vulnerability as it allows users with specific permissions to grant memberships improperly.
2
How do I fix CVE-2004-0703?
To fix CVE-2004-0703, upgrade to a patched version of Bugzilla that addresses this vulnerability.
3
Which versions of Bugzilla are affected by CVE-2004-0703?
CVE-2004-0703 affects Bugzilla versions from 2.17.1 through 2.17.7 and 2.10 to 2.17.7.
4
What type of user privileges are required to exploit CVE-2004-0703?
Exploitation of CVE-2004-0703 requires users to have 'grant membership' privileges.
5
What does CVE-2004-0703 allow users to do?
CVE-2004-0703 allows users with granted privileges to assign memberships to any group within Bugzilla, including those not controlled by them.