CVE-2012-4189: XSS
Published Nov 16, 2012
·Updated
Cross-site scripting (XSS) vulnerability in Bugzilla 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1, allows remote attackers to inject arbitrary web script or HTML via a field value that is not properly handled during construction of a tabular report, as demonstrated by the Version field.
Affected Software
14 affected components
Bugzilla=4.1
Bugzilla=4.1.1
Bugzilla=4.1.2
Bugzilla=4.1.3
Bugzilla=4.2
Bugzilla=4.2-rc1
Bugzilla=4.2-rc2
Bugzilla=4.2.1
Bugzilla=4.2.2
Bugzilla=4.2.3
Bugzilla=4.3
Bugzilla=4.3.1
Bugzilla=4.3.2
Bugzilla=4.3.3
Remediation
Patch Available
Event History
Nov 16, 2012
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4189?
CVE-2012-4189 is classified as a medium severity Cross-site Scripting (XSS) vulnerability.
2
How do I fix CVE-2012-4189?
To fix CVE-2012-4189, upgrade Bugzilla to version 4.2.4 or later, or 4.4rc1 or later.
3
What versions of Bugzilla are affected by CVE-2012-4189?
CVE-2012-4189 affects Bugzilla versions 4.1.x, 4.2.x prior to 4.2.4, and 4.3.x and 4.4.x prior to 4.4rc1.
4
What type of vulnerability is CVE-2012-4189?
CVE-2012-4189 is a Cross-site Scripting (XSS) vulnerability.
5
Can CVE-2012-4189 allow remote attacks?
Yes, CVE-2012-4189 allows remote attackers to inject arbitrary web scripts or HTML.