CVE-2012-4747: Medium severity bugzilla vulnerability
Bugzilla 2.x and 3.x through 3.6.11, 3.7.x and 4.0.x before 4.0.8, 4.1.x and 4.2.x before 4.2.3, and 4.3.x before 4.3.3 stores potentially sensitive information under the web root with insufficient access control, which allows remote attackers to read (1) template (aka .tmpl) files, (2) other custom extension files under extensions/, or (3) custom documentation files under docs/ via a direct request.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4747?
CVE-2012-4747 has been classified as a moderate severity vulnerability.
How do I fix CVE-2012-4747?
To fix CVE-2012-4747, upgrade Bugzilla to versions 4.0.8, 4.2.3, or 4.3.3 and later.
What versions of Bugzilla are affected by CVE-2012-4747?
CVE-2012-4747 affects Bugzilla versions 2.x, 3.x up to 3.6.11, 3.7.x, and 4.0.x up to 4.0.7, as well as 4.1.x and 4.2.x prior to 4.2.3 and 4.3.x prior to 4.3.3.
What kind of information can attackers access due to CVE-2012-4747?
Attackers can potentially access sensitive information stored under the web root, including template files and other custom data.
Is it safe to use Bugzilla versions after the fixes for CVE-2012-4747?
Yes, using Bugzilla versions 4.0.8, 4.2.3, or 4.3.3 and later mitigates the vulnerabilities associated with CVE-2012-4747.