CVE-2012-0453: CSRF
Cross-site request forgery (CSRF) vulnerability in xmlrpc.cgi in Bugzilla 4.0.2 through 4.0.4 and 4.1.1 through 4.2rc2, when modperl is used, allows remote attackers to hijack the authentication of arbitrary users for requests that modify the product's installation via the XML-RPC API.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0453?
CVE-2012-0453 is classified as a medium severity vulnerability due to its potential to allow unauthorized actions through CSRF.
How do I fix CVE-2012-0453?
To fix CVE-2012-0453, upgrade Bugzilla to version 4.0.5 or later, or apply the provided security patches.
What versions are affected by CVE-2012-0453?
CVE-2012-0453 affects Bugzilla versions 4.0.2 through 4.0.4 and 4.1.1 through 4.2rc2.
What type of vulnerability is CVE-2012-0453?
CVE-2012-0453 is a Cross-Site Request Forgery (CSRF) vulnerability.
Who can exploit CVE-2012-0453?
Remote attackers can exploit CVE-2012-0453 to hijack user authentication and perform unauthorized modifications.