CVE-2007-4539: Medium severity Bugzilla vulnerability
The WebService (XML-RPC) interface in Bugzilla 2.23.3 through 3.0.0 does not enforce permissions for the time-tracking fields of bugs, which allows remote attackers to obtain sensitive information via certain XML-RPC requests, as demonstrated by the (1) Deadline and (2) Estimated Time fields.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4539?
CVE-2007-4539 is classified as a medium severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2007-4539?
Fix CVE-2007-4539 by updating Bugzilla to a version that addresses this vulnerability, specifically versions later than 3.0.0.
What is affected by CVE-2007-4539?
CVE-2007-4539 affects Bugzilla versions 2.23.3 through 3.0.0.
What type of information can be leaked due to CVE-2007-4539?
CVE-2007-4539 allows unauthorized access to time-tracking fields such as Deadline and Estimated Time.
How can attackers exploit CVE-2007-4539?
Attackers can exploit CVE-2007-4539 through specific XML-RPC requests that do not enforce proper permissions.