CVE-2012-0465: Medium severity bugzilla vulnerability
Bugzilla 3.5.x and 3.6.x before 3.6.9, 3.7.x and 4.0.x before 4.0.6, and 4.1.x and 4.2.x before 4.2.1, when the inboundproxies option is enabled, does not properly validate the X-Forwarded-For HTTP header, which allows remote attackers to bypass the lockout policy via a series of authentication requests with (1) different IP address strings in this header or (2) a long string in this header.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0465?
CVE-2012-0465 is considered a medium severity vulnerability due to the potential for authentication bypass.
How do I fix CVE-2012-0465?
To mitigate CVE-2012-0465, upgrade Bugzilla to version 3.6.9, 4.0.6, or 4.2.1 or later.
What systems are affected by CVE-2012-0465?
CVE-2012-0465 affects Bugzilla versions 3.5.x up to 3.5.8, 3.6.x up to 3.6.8, 3.7.x, and 4.0.x up to 4.0.5.
What functionality is impacted by CVE-2012-0465?
CVE-2012-0465 allows remote attackers to bypass lockout policies, compromising account security.
Is CVE-2012-0465 specific to any configurations of Bugzilla?
Yes, CVE-2012-0465 occurs when the inbound_proxies option is enabled in Bugzilla's configuration.