CVE-2014-8630: Command Injection
Bugzilla before 4.0.16, 4.1.x and 4.2.x before 4.2.12, 4.3.x and 4.4.x before 4.4.7, and 5.x before 5.0rc1 allows remote authenticated users to execute arbitrary commands by leveraging the editcomponents privilege and triggering crafted input to a two-argument Perl open call, as demonstrated by shell metacharacters in a product name.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8630?
CVE-2014-8630 is classified as a high severity vulnerability due to the ability for remote authenticated users to execute arbitrary commands.
How do I fix CVE-2014-8630?
To fix CVE-2014-8630, upgrade Bugzilla to the latest versions or ensure you are using Bugzilla 4.0.16 or later, 4.2.12 or later, 4.4.7 or later, or 5.0rc1 or later.
Which versions of Bugzilla are affected by CVE-2014-8630?
CVE-2014-8630 affects Bugzilla versions prior to 4.0.16, all 4.1.x and 4.2.x versions before 4.2.12, all 4.3.x versions before 4.4.7, and all 5.x versions before 5.0rc1.
Who can exploit CVE-2014-8630?
CVE-2014-8630 can be exploited by remote authenticated users with the editcomponents privilege in Bugzilla.
What kind of damage can CVE-2014-8630 cause?
CVE-2014-8630 can allow attackers to execute arbitrary commands on the system, potentially leading to full system compromise.