CVE-2014-1517: CSRF
The login form in Bugzilla 2.x, 3.x, 4.x before 4.4.3, and 4.5.x before 4.5.3 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account and then submit a vulnerability report, related to a "login CSRF" issue.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1517?
CVE-2014-1517 has a medium severity rating due to its potential to expose sensitive user information.
How do I fix CVE-2014-1517?
To fix CVE-2014-1517, update Bugzilla to version 4.4.3 or later.
Who is affected by CVE-2014-1517?
CVE-2014-1517 affects all versions of Bugzilla from 2.x to 4.5.x before 4.5.3.
What type of vulnerability is CVE-2014-1517?
CVE-2014-1517 is a vulnerability related to authentication issues in the Bugzilla login process.
What can attackers do with CVE-2014-1517?
Attackers can exploit CVE-2014-1517 to obtain sensitive information by tricking victims into logging into their accounts.