CVE-2015-8509: Infoleak
Template.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.16, 4.3.x and 4.4.x before 4.4.11, and 4.5.x and 5.0.x before 5.0.2 does not properly construct CSV files, which allows remote attackers to obtain sensitive information by leveraging a web browser that interprets CSV data as JavaScript code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8509?
CVE-2015-8509 is classified as a moderate severity vulnerability due to the potential for information leakage.
How do I fix CVE-2015-8509?
You can fix CVE-2015-8509 by upgrading to Bugzilla version 4.2.16, 4.4.11, or 5.0.2 or later.
Who is affected by CVE-2015-8509?
CVE-2015-8509 affects Bugzilla versions 2.x, 3.x, and certain 4.x and 5.x versions prior to their respective fixes.
What type of vulnerability is CVE-2015-8509?
CVE-2015-8509 is a vulnerability that allows remote attackers to obtain sensitive information through improper construction of CSV files.
Can CVE-2015-8509 lead to XSS attacks?
CVE-2015-8509 can potentially lead to XSS attacks as it allows CSV data to be interpreted as JavaScript code by web browsers.