CVE-2009-3387: Medium severity Bugzilla vulnerability
Bugzilla 3.3.1 through 3.4.4, 3.5.1, and 3.5.2 does not allow group restrictions to be preserved throughout the process of moving a bug to a different product category, which allows remote attackers to obtain sensitive information via a request for a bug in opportunistic circumstances.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3387?
CVE-2009-3387 has a moderate severity level due to its potential for exposing sensitive information.
How do I fix CVE-2009-3387?
To fix CVE-2009-3387, users should upgrade Bugzilla to a version that addresses this vulnerability, specifically a version higher than 3.5.2.
What versions of Bugzilla are affected by CVE-2009-3387?
CVE-2009-3387 affects Bugzilla versions 3.3.1 through 3.4.4, and versions 3.5.1 and 3.5.2.
What kind of attacks are possible with CVE-2009-3387?
CVE-2009-3387 may allow remote attackers to access sensitive bug information that should be restricted by group permissions.
Is there a workaround for CVE-2009-3387?
There is no known workaround for CVE-2009-3387; the only solution is to update to a patched version of Bugzilla.