CVE-2009-0482: CSRF
Cross-site request forgery (CSRF) vulnerability in Bugzilla before 3.2 before 3.2.1, 3.3 before 3.3.2, and other versions before 3.2 allows remote attackers to perform bug updating activities as other users via a link or IMG tag to processbug.cgi.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Bugzillato a version that resolves this vulnerability.Fixed in 3.2.1 - Upgrade
Upgrade
Bugzillato a version that resolves this vulnerability.Fixed in 3.3.2
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0482?
CVE-2009-0482 has been classified as a moderate severity vulnerability.
How do I fix CVE-2009-0482?
To fix CVE-2009-0482, upgrade Bugzilla to version 3.2.1 or later.
What type of vulnerability is CVE-2009-0482?
CVE-2009-0482 is a Cross-site request forgery (CSRF) vulnerability.
Which versions of Bugzilla are affected by CVE-2009-0482?
Versions of Bugzilla prior to 3.2.1 and 3.3.2 are affected by CVE-2009-0482.
What can attackers achieve with CVE-2009-0482?
Attackers can perform bug updating activities as other users through a crafted link or IMG tag.