CVE-2010-1204: Medium severity bugzilla vulnerability
Published Jun 28, 2010
·Updated
Search.pm in Bugzilla 2.17.1 through 3.2.6, 3.3.1 through 3.4.6, 3.5.1 through 3.6, and 3.7 allows remote attackers to obtain potentially sensitive time-tracking information via a crafted search URL, related to a "boolean chart search."
Affected Software
44 affected components
Bugzilla=3.0.4
Bugzilla=3.1.3
Bugzilla=3.4.3
Bugzilla=3.0.1
Bugzilla=2.17.6
Bugzilla=3.2.6
Bugzilla=3.1.1
Bugzilla=3.7
Bugzilla=3.4.2
Bugzilla=3.1.2
Bugzilla=3.5.3
Bugzilla=3.2.5
Bugzilla=3.3.4
Bugzilla=3.6
Bugzilla=2.17.4
Bugzilla=2.17.1
Bugzilla=3.2.3
Bugzilla=3.5.2
Bugzilla=3.0
Bugzilla=3.5.1
Bugzilla=3.0.11
Bugzilla=3.0.6
Bugzilla=3.0.7
Bugzilla=3.4.1
Bugzilla=3.4.4
Bugzilla=3.1.4
Bugzilla=2.17.5
Bugzilla=2.17.3
Bugzilla=3.0.3
Bugzilla=3.2
Bugzilla=3.0.9
Bugzilla=3.2.4
Bugzilla=3.0.2
Bugzilla=3.3.3
Bugzilla=3.2.2
Bugzilla=2.17.7
Bugzilla=3.0.10
Bugzilla=3.4
Bugzilla=3.0.8
Bugzilla=3.4.5
Bugzilla=3.0.5
Bugzilla=3.2.1
Bugzilla=3.3.1
Bugzilla=3.4.6
Event History
Jun 28, 2010
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-1204?
CVE-2010-1204 is considered a medium severity vulnerability due to the potential exposure of sensitive time-tracking information.
2
How do I fix CVE-2010-1204?
To fix CVE-2010-1204, upgrade Bugzilla to a version later than 3.4.6.
3
Which versions of Bugzilla are affected by CVE-2010-1204?
CVE-2010-1204 affects Bugzilla versions 2.17.1 through 3.2.6, and 3.3.1 through 3.4.6, 3.5.1 through 3.6, and 3.7.
4
What type of information can be exposed due to CVE-2010-1204?
CVE-2010-1204 can expose potentially sensitive time-tracking information.
5
How does CVE-2010-1204 operate?
CVE-2010-1204 operates through the manipulation of crafted search URLs to gain unauthorized access to information.