CVE-2009-0484: CSRF
Published Feb 9, 2009
·Updated
Cross-site request forgery (CSRF) vulnerability in Bugzilla 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delete shared or saved searches via a link or IMG tag to buglist.cgi.
Affected Software
9 affected components
Bugzilla=3.0.4
Bugzilla=3.0.0
Bugzilla=3.0.1
Bugzilla=3.0.6
Bugzilla=3.0.3
Bugzilla=3.2
Bugzilla=3.0.2
Bugzilla=3.0.5
Bugzilla=3.3.1
Event History
Feb 9, 2009
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-0484?
CVE-2009-0484 has a moderate severity rating due to its ability to enable unauthorized deletion of searches.
2
How do I fix CVE-2009-0484?
To fix CVE-2009-0484, upgrade Bugzilla to version 3.0.7 or later, or apply the appropriate patches.
3
Which versions of Bugzilla are affected by CVE-2009-0484?
CVE-2009-0484 affects Bugzilla versions prior to 3.0.7, 3.2 prior to 3.2.1, and 3.3 prior to 3.3.2.
4
What type of vulnerability is CVE-2009-0484?
CVE-2009-0484 is a cross-site request forgery (CSRF) vulnerability.
5
What can an attacker do with CVE-2009-0484?
An attacker exploiting CVE-2009-0484 can delete shared or saved searches without user consent.