CVE-2011-3667: Medium severity bugzilla vulnerability
The User.offeraccountbyemail WebService method in Bugzilla 2.x and 3.x before 3.4.13, 3.5.x and 3.6.x before 3.6.7, 3.7.x and 4.0.x before 4.0.3, and 4.1.x through 4.1.3, when createemailregexp is not empty, does not properly handle usercancreateaccount settings, which allows remote attackers to create user accounts by leveraging a token contained in an e-mail message.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3667?
CVE-2011-3667 is considered a high severity vulnerability due to its potential to allow unauthorized account creation.
How do I fix CVE-2011-3667?
To fix CVE-2011-3667, upgrade Bugzilla to the latest version, specifically to 3.4.13 or later.
What software versions are affected by CVE-2011-3667?
CVE-2011-3667 affects Bugzilla versions 2.x, 3.x before 3.4.13, and several versions up to 4.1.3.
What type of vulnerability is CVE-2011-3667?
CVE-2011-3667 is an account creation vulnerability that can be exploited by remote attackers.
Who is impacted by CVE-2011-3667?
Any users or organizations running affected versions of Bugzilla are impacted by CVE-2011-3667.