CVE-2008-6098: Medium severity Bugzilla vulnerability
Bugzilla 3.2 before 3.2 RC2, 3.0 before 3.0.6, 2.22 before 2.22.6, 2.20 before 2.20.7, and other versions after 2.17.4 allows remote authenticated users to bypass moderation to approve and disapprove quips via a direct request to quips.cgi with the action parameter set to "approve."
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Bugzillato a version that resolves this vulnerability.Fixed in 3.2 RC2 - Upgrade
Upgrade
Bugzillato a version that resolves this vulnerability.Fixed in 3.0.6 - Upgrade
Upgrade
Bugzillato a version that resolves this vulnerability.Fixed in 2.22.6 - Upgrade
Upgrade
Bugzillato a version that resolves this vulnerability.Fixed in 2.20.7
Event History
Frequently Asked Questions
What is the severity of CVE-2008-6098?
The severity of CVE-2008-6098 is typically classified as medium, as it allows authenticated users to bypass moderation controls.
How do I fix CVE-2008-6098?
To fix CVE-2008-6098, update Bugzilla to version 3.2 RC2 or later for version 3.2, 3.0.6 for version 3.0, or appropriate fixes for other affected versions.
Who is affected by CVE-2008-6098?
CVE-2008-6098 affects Bugzilla versions prior to 3.2 RC2, including various versions of 3.0, 2.22, and earlier.
What type of vulnerability is CVE-2008-6098?
CVE-2008-6098 is a moderation bypass vulnerability that affects how quips are approved or disapproved in Bugzilla.
Is the exploitation of CVE-2008-6098 common?
While the exploit requires authenticated access, if exploited, it can lead to unauthorized approvals, making it a potential risk in environments with multiple users.