CVE-2009-0485: CSRF
Published Feb 9, 2009
·Updated
Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.17 to 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delete unused flag types via a link or IMG tag to editflagtypes.cgi.
Affected Software
54 affected components
Bugzilla=3.0.4
Bugzilla=3.0-rc1
Bugzilla=2.18.6\+
Bugzilla=3.0.1
Bugzilla=2.17.6
Bugzilla=3.2-rc1
Bugzilla=2.18.5
Bugzilla=2.19.3
Bugzilla=2.20-rc2
Bugzilla=2.18.6
Bugzilla=2.20-rc1
Bugzilla=2.20
Bugzilla=2.19
Bugzilla=2.18-rc1
Bugzilla=2.20.5
Bugzilla=2.20.6
Bugzilla=2.22.3
Bugzilla=2.22.6
Bugzilla=2.17.4
Bugzilla=2.17.1
Bugzilla=2.22.1
Bugzilla=3.0
Bugzilla=3.0.6
Bugzilla=2.20.1
Bugzilla=2.22.2
Bugzilla=2.18.1
Bugzilla=2.22-rc1
Bugzilla=2.22.5
Bugzilla=2.19.1
Bugzilla=2.17.5
Bugzilla=2.22
Bugzilla=2.17.3
Bugzilla=3.0.3
Bugzilla=3.2
Bugzilla=2.20.3
Bugzilla=3.0.2
Bugzilla=2.18.4
Bugzilla=2.18
Bugzilla=2.18.3
Bugzilla=2.17.7
Bugzilla=2.20.7
Bugzilla=2.20.2
Bugzilla=2.20.4
Bugzilla=2.21.1
Bugzilla=2.18-rc3
Bugzilla=2.17
Bugzilla=2.18.2
Bugzilla=2.18-rc2
Bugzilla=3.2-rc2
Bugzilla=3.0.5
Bugzilla=2.22.4
Bugzilla=2.21
Bugzilla=3.3.1
Bugzilla=2.19.2
Event History
Feb 9, 2009
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-0485?
CVE-2009-0485 has been classified as a medium severity vulnerability due to the potential for exploitation via CSRF.
2
How do I fix CVE-2009-0485?
To fix CVE-2009-0485, upgrade Bugzilla to version 3.0.7 or later, or to version 3.2.1 or later.
3
Which versions of Bugzilla are affected by CVE-2009-0485?
CVE-2009-0485 affects Bugzilla versions from 2.17 to 2.22.7 and 3.0 before 3.0.7.
4
How does CVE-2009-0485 work?
CVE-2009-0485 allows attackers to perform unauthorized actions on behalf of a user due to a lack of anti-CSRF protections.
5
Can I exploit CVE-2009-0485 remotely?
Yes, CVE-2009-0485 can be exploited remotely through crafted links or image tags.