First published: Wed May 07 2008(Updated: )
The WebService in Bugzilla 3.1.3 allows remote authenticated users without canconfirm privileges to create NEW or ASSIGNED bug entries via a request to the XML-RPC interface, which bypasses the canconfirm check.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Bugzilla | =3.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2104 has a medium severity rating due to the risk of unauthorized bug entry creation.
To fix CVE-2008-2104, upgrade Bugzilla to a version that addresses this vulnerability, ensuring users have appropriate permissions.
Remote authenticated users in Bugzilla 3.1.3 without canconfirm privileges are primarily affected by CVE-2008-2104.
CVE-2008-2104 is a permission bypass vulnerability in the Bugzilla XML-RPC interface.
Yes, CVE-2008-2104 can potentially lead to data integrity issues by allowing unauthorized users to create or modify bug entries.