CVE-2014-1546: CSRF
The response function in the JSONP endpoint in WebService/Server/JSONRPC.pm in jsonrpc.cgi in Bugzilla 3.x and 4.x before 4.0.14, 4.1.x and 4.2.x before 4.2.10, 4.3.x and 4.4.x before 4.4.5, and 4.5.x before 4.5.5 accepts certain long callback values and does not restrict the initial bytes of a JSONP response, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and obtain sensitive information, via a crafted OBJECT element with SWF content consistent with the bzcallback character set.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1546?
CVE-2014-1546 has been classified as a moderate severity vulnerability due to its potential impact on user data integrity.
How do I fix CVE-2014-1546?
To fix CVE-2014-1546, you should upgrade to Bugzilla version 4.0.14, 4.2.10, 4.4.5, or 4.5.5 or later.
What types of Bugzilla versions are affected by CVE-2014-1546?
CVE-2014-1546 affects Bugzilla versions 3.x and 4.x prior to specified updates.
What is the nature of the vulnerability in CVE-2014-1546?
The vulnerability in CVE-2014-1546 allows for exploitation via long callback values in JSONP responses, which may lead to unexpected behavior.
Are there known exploits for CVE-2014-1546?
As of the last updates, there have been no widely reported known exploits for CVE-2014-1546.