First published: Mon Oct 13 2014(Updated: )
Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not ensure that a scalar context is used for certain CGI parameters, which allows remote attackers to conduct cross-site scripting (XSS) attacks by sending three values for a single parameter name.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fedoraproject Fedora | =19 | |
Fedoraproject Fedora | =20 | |
Fedoraproject Fedora | =21 | |
Mozilla Bugzilla | =2.0 | |
Mozilla Bugzilla | =2.2 | |
Mozilla Bugzilla | =2.4 | |
Mozilla Bugzilla | =2.6 | |
Mozilla Bugzilla | =2.8 | |
Mozilla Bugzilla | =2.9 | |
Mozilla Bugzilla | =2.10 | |
Mozilla Bugzilla | =2.12 | |
Mozilla Bugzilla | =2.14 | |
Mozilla Bugzilla | =2.14.1 | |
Mozilla Bugzilla | =2.14.2 | |
Mozilla Bugzilla | =2.14.3 | |
Mozilla Bugzilla | =2.14.4 | |
Mozilla Bugzilla | =2.14.5 | |
Mozilla Bugzilla | =2.16 | |
Mozilla Bugzilla | =2.16-rc1 | |
Mozilla Bugzilla | =2.16-rc2 | |
Mozilla Bugzilla | =2.16.1 | |
Mozilla Bugzilla | =2.16.2 | |
Mozilla Bugzilla | =2.16.3 | |
Mozilla Bugzilla | =2.16.4 | |
Mozilla Bugzilla | =2.16.5 | |
Mozilla Bugzilla | =2.16.6 | |
Mozilla Bugzilla | =2.16.7 | |
Mozilla Bugzilla | =2.16.8 | |
Mozilla Bugzilla | =2.16.9 | |
Mozilla Bugzilla | =2.16.10 | |
Mozilla Bugzilla | =2.16.11 | |
Mozilla Bugzilla | =2.16_rc2 | |
Mozilla Bugzilla | =2.17 | |
Mozilla Bugzilla | =2.17.1 | |
Mozilla Bugzilla | =2.17.2 | |
Mozilla Bugzilla | =2.17.3 | |
Mozilla Bugzilla | =2.17.4 | |
Mozilla Bugzilla | =2.17.5 | |
Mozilla Bugzilla | =2.17.6 | |
Mozilla Bugzilla | =2.17.7 | |
Mozilla Bugzilla | =2.18 | |
Mozilla Bugzilla | =2.18-rc1 | |
Mozilla Bugzilla | =2.18-rc2 | |
Mozilla Bugzilla | =2.18-rc3 | |
Mozilla Bugzilla | =2.18.1 | |
Mozilla Bugzilla | =2.18.2 | |
Mozilla Bugzilla | =2.18.3 | |
Mozilla Bugzilla | =2.18.4 | |
Mozilla Bugzilla | =2.18.5 | |
Mozilla Bugzilla | =2.18.6 | |
Mozilla Bugzilla | =2.18.6\+ | |
Mozilla Bugzilla | =2.18.7 | |
Mozilla Bugzilla | =2.18.8 | |
Mozilla Bugzilla | =2.18.9 | |
Mozilla Bugzilla | =2.19 | |
Mozilla Bugzilla | =2.19.1 | |
Mozilla Bugzilla | =2.19.2 | |
Mozilla Bugzilla | =2.19.3 | |
Mozilla Bugzilla | =2.20 | |
Mozilla Bugzilla | =2.20-rc1 | |
Mozilla Bugzilla | =2.20-rc2 | |
Mozilla Bugzilla | =2.20.1 | |
Mozilla Bugzilla | =2.20.2 | |
Mozilla Bugzilla | =2.20.3 | |
Mozilla Bugzilla | =2.20.4 | |
Mozilla Bugzilla | =2.20.5 | |
Mozilla Bugzilla | =2.20.6 | |
Mozilla Bugzilla | =2.20.7 | |
Mozilla Bugzilla | =2.21 | |
Mozilla Bugzilla | =2.21.1 | |
Mozilla Bugzilla | =2.21.2 | |
Mozilla Bugzilla | =2.21.2-rc1 | |
Mozilla Bugzilla | =2.22 | |
Mozilla Bugzilla | =2.22-rc1 | |
Mozilla Bugzilla | =2.22.1 | |
Mozilla Bugzilla | =2.22.2 | |
Mozilla Bugzilla | =2.22.3 | |
Mozilla Bugzilla | =2.22.4 | |
Mozilla Bugzilla | =2.22.5 | |
Mozilla Bugzilla | =2.22.6 | |
Mozilla Bugzilla | =2.22.7 | |
Mozilla Bugzilla | =2.23 | |
Mozilla Bugzilla | =2.23.1 | |
Mozilla Bugzilla | =2.23.2 | |
Mozilla Bugzilla | =2.23.3 | |
Mozilla Bugzilla | =2.23.4 | |
Mozilla Bugzilla | =3.0 | |
Mozilla Bugzilla | =3.0-rc1 | |
Mozilla Bugzilla | =3.0.0 | |
Mozilla Bugzilla | =3.0.1 | |
Mozilla Bugzilla | =3.0.2 | |
Mozilla Bugzilla | =3.0.3 | |
Mozilla Bugzilla | =3.0.4 | |
Mozilla Bugzilla | =3.0.5 | |
Mozilla Bugzilla | =3.0.6 | |
Mozilla Bugzilla | =3.0.7 | |
Mozilla Bugzilla | =3.0.8 | |
Mozilla Bugzilla | =3.0.9 | |
Mozilla Bugzilla | =3.0.10 | |
Mozilla Bugzilla | =3.0.11 | |
Mozilla Bugzilla | =3.0_rc1 | |
Mozilla Bugzilla | =3.1.0 | |
Mozilla Bugzilla | =3.1.1 | |
Mozilla Bugzilla | =3.1.2 | |
Mozilla Bugzilla | =3.1.3 | |
Mozilla Bugzilla | =3.1.4 | |
Mozilla Bugzilla | =3.2 | |
Mozilla Bugzilla | =3.2-rc1 | |
Mozilla Bugzilla | =3.2-rc2 | |
Mozilla Bugzilla | =3.2.1 | |
Mozilla Bugzilla | =3.2.2 | |
Mozilla Bugzilla | =3.2.3 | |
Mozilla Bugzilla | =3.2.4 | |
Mozilla Bugzilla | =3.2.5 | |
Mozilla Bugzilla | =3.2.6 | |
Mozilla Bugzilla | =3.2.7 | |
Mozilla Bugzilla | =3.2.8 | |
Mozilla Bugzilla | =3.2.9 | |
Mozilla Bugzilla | =3.2.10 | |
Mozilla Bugzilla | =3.3 | |
Mozilla Bugzilla | =3.3.1 | |
Mozilla Bugzilla | =3.3.2 | |
Mozilla Bugzilla | =3.3.3 | |
Mozilla Bugzilla | =3.3.4 | |
Mozilla Bugzilla | =3.4 | |
Mozilla Bugzilla | =3.4-rc1 | |
Mozilla Bugzilla | =3.4.1 | |
Mozilla Bugzilla | =3.4.2 | |
Mozilla Bugzilla | =3.4.3 | |
Mozilla Bugzilla | =3.4.4 | |
Mozilla Bugzilla | =3.4.5 | |
Mozilla Bugzilla | =3.4.6 | |
Mozilla Bugzilla | =3.4.7 | |
Mozilla Bugzilla | =3.4.8 | |
Mozilla Bugzilla | =3.4.9 | |
Mozilla Bugzilla | =3.4.10 | |
Mozilla Bugzilla | =3.4.11 | |
Mozilla Bugzilla | =3.4.12 | |
Mozilla Bugzilla | =3.4.13 | |
Mozilla Bugzilla | =3.5 | |
Mozilla Bugzilla | =3.5.1 | |
Mozilla Bugzilla | =3.5.2 | |
Mozilla Bugzilla | =3.5.3 | |
Mozilla Bugzilla | =3.6 | |
Mozilla Bugzilla | =3.6-rc1 | |
Mozilla Bugzilla | =3.6.0 | |
Mozilla Bugzilla | =3.6.1 | |
Mozilla Bugzilla | =3.6.2 | |
Mozilla Bugzilla | =3.6.3 | |
Mozilla Bugzilla | =3.6.4 | |
Mozilla Bugzilla | =3.6.5 | |
Mozilla Bugzilla | =3.6.6 | |
Mozilla Bugzilla | =3.6.7 | |
Mozilla Bugzilla | =3.6.8 | |
Mozilla Bugzilla | =3.6.9 | |
Mozilla Bugzilla | =3.6.10 | |
Mozilla Bugzilla | =3.6.11 | |
Mozilla Bugzilla | =3.6.12 | |
Mozilla Bugzilla | =3.6.13 | |
Mozilla Bugzilla | =3.7 | |
Mozilla Bugzilla | =3.7.1 | |
Mozilla Bugzilla | =3.7.2 | |
Mozilla Bugzilla | =3.7.3 | |
Mozilla Bugzilla | =4.0 | |
Mozilla Bugzilla | =4.0-rc1 | |
Mozilla Bugzilla | =4.0-rc2 | |
Mozilla Bugzilla | =4.0.1 | |
Mozilla Bugzilla | =4.0.10 | |
Mozilla Bugzilla | =4.0.11 | |
Mozilla Bugzilla | =4.0.12 | |
Mozilla Bugzilla | =4.0.13 | |
Mozilla Bugzilla | =4.0.14 | |
Mozilla Bugzilla | =4.1 | |
Mozilla Bugzilla | =4.1.1 | |
Mozilla Bugzilla | =4.1.2 | |
Mozilla Bugzilla | =4.1.3 | |
Mozilla Bugzilla | =4.2 | |
Mozilla Bugzilla | =4.2-rc1 | |
Mozilla Bugzilla | =4.2-rc2 | |
Mozilla Bugzilla | =4.2.1 | |
Mozilla Bugzilla | =4.2.2 | |
Mozilla Bugzilla | =4.2.3 | |
Mozilla Bugzilla | =4.2.4 | |
Mozilla Bugzilla | =4.2.5 | |
Mozilla Bugzilla | =4.2.6 | |
Mozilla Bugzilla | =4.2.7 | |
Mozilla Bugzilla | =4.2.8 | |
Mozilla Bugzilla | =4.2.9 | |
Mozilla Bugzilla | =4.2.10 | |
Mozilla Bugzilla | =4.3 | |
Mozilla Bugzilla | =4.3.1 | |
Mozilla Bugzilla | =4.3.2 | |
Mozilla Bugzilla | =4.3.3 | |
Mozilla Bugzilla | =4.4 | |
Mozilla Bugzilla | =4.4-rc1 | |
Mozilla Bugzilla | =4.4-rc2 | |
Mozilla Bugzilla | =4.4.1 | |
Mozilla Bugzilla | =4.4.2 | |
Mozilla Bugzilla | =4.4.3 | |
Mozilla Bugzilla | =4.4.4 | |
Mozilla Bugzilla | =4.4.5 | |
Mozilla Bugzilla | =4.5 | |
Mozilla Bugzilla | =4.5.1 | |
Mozilla Bugzilla | =4.5.2 | |
Mozilla Bugzilla | =4.5.3 | |
Mozilla Bugzilla | =4.5.4 | |
Mozilla Bugzilla | =4.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1573 has a moderate severity rating due to its potential to allow cross-site scripting (XSS) attacks.
To fix CVE-2014-1573, users should upgrade to Bugzilla version 4.0.15, 4.2.11, 4.4.6, or 4.5.6 or later.
Bugzilla versions 2.x through 4.0.x before 4.0.15, 4.1.x, 4.2.x before 4.2.11, 4.3.x, and 4.4.x before 4.4.6 are affected.
CVE-2014-1573 is a cross-site scripting (XSS) vulnerability that affects certain CGI parameters.
Using affected versions of Bugzilla without applying the necessary updates poses a risk of exploitation through XSS attacks.