CVE-2004-1634: Medium severity Bugzilla vulnerability
showbug.cgi in Bugzilla 2.17.1 through 2.18rc2 and 2.19 from CVS, when using the insidergroup feature and exporting a bug to XML, shows comments and attachment summaries which are marked as private, which allows remote attackers to gain sensitive information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1634?
CVE-2004-1634 is classified as a medium severity vulnerability due to its potential to expose private comments and attachment summaries.
How do I fix CVE-2004-1634?
To fix CVE-2004-1634, upgrade to Bugzilla version 2.18 or later where this issue has been resolved.
What systems are affected by CVE-2004-1634?
CVE-2004-1634 affects Bugzilla versions 2.17.1 through 2.18rc2 and various earlier versions.
What type of vulnerability is CVE-2004-1634?
CVE-2004-1634 is an information disclosure vulnerability that allows remote attackers to access sensitive information.
Is CVE-2004-1634 a remote attack vulnerability?
Yes, CVE-2004-1634 can be exploited remotely, allowing attackers to retrieve private data without authentication.