CVE-2011-2379: XSS
Cross-site scripting (XSS) vulnerability in Bugzilla 2.4 through 2.22.7, 3.0.x through 3.3.x, 3.4.x before 3.4.12, 3.5.x, 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.3, when Internet Explorer before 9 or Safari before 5.0.6 is used for Raw Unified mode, allows remote attackers to inject arbitrary web script or HTML via a crafted patch, related to content sniffing.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2379?
CVE-2011-2379 has a medium severity level due to its cross-site scripting vulnerability.
How do I fix CVE-2011-2379?
To fix CVE-2011-2379, upgrade Bugzilla to version 4.1.3 or later.
Which versions of Bugzilla are affected by CVE-2011-2379?
CVE-2011-2379 affects Bugzilla versions 2.4 through 2.22.7 and various versions of 3.x up to 4.0.1.
What types of browsers are vulnerable with CVE-2011-2379?
CVE-2011-2379 is notably vulnerable on Internet Explorer versions before 9 and Safari versions before 5.0.6.
Can CVE-2011-2379 be exploited by remote attackers?
Yes, CVE-2011-2379 allows remote attackers to execute arbitrary script code in the context of a user's session.