CVE-2011-0046: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 allow remote attackers to hijack the authentication of arbitrary users for requests related to (1) adding a saved search in buglist.cgi, (2) voting in votes.cgi, (3) sanity checking in sanitycheck.cgi, (4) creating or editing a chart in chart.cgi, (5) column changing in colchange.cgi, and (6) adding, deleting, or approving a quip in quips.cgi.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0046?
CVE-2011-0046 is considered a moderate severity vulnerability that allows attackers to execute unauthorized actions on behalf of users.
What applications are affected by CVE-2011-0046?
CVE-2011-0046 affects multiple versions of Mozilla Bugzilla including versions prior to 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2.
How do I fix CVE-2011-0046?
To fix CVE-2011-0046, users should upgrade Bugzilla to the latest version available that patches this vulnerability.
What type of vulnerability is CVE-2011-0046?
CVE-2011-0046 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
What actions can an attacker perform using CVE-2011-0046?
An attacker exploiting CVE-2011-0046 could hijack user authentication to perform actions such as adding saved searches or voting in Bugzilla.