CVE-2018-5123: CSRF
Published Apr 29, 2019
·Updated
A third party website can access information available to a user with access to a restricted bug entry using the image generation in report.cgi in all Bugzilla versions prior to 4.4.
Affected Software
1 affected component
Bugzilla<4.4
Remediation
Patch Available
Event History
Apr 29, 2019
CVE Published
via MITRE·03:34 PM
Data Sourced
via MITRE·03:34 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2018-5123?
CVE-2018-5123 is a vulnerability in Bugzilla versions prior to 4.4 that allows a third-party website to access information from a restricted bug entry.
2
How severe is CVE-2018-5123?
CVE-2018-5123 has a severity score of 8.8, which is considered high.
3
Which software versions are affected by CVE-2018-5123?
All Bugzilla versions prior to 4.4 are affected by CVE-2018-5123.
4
How can I fix CVE-2018-5123?
To fix CVE-2018-5123, upgrade to Bugzilla version 4.4 or later.
5
Where can I find more information about CVE-2018-5123?
You can find more information about CVE-2018-5123 at the following link: [CVE-2018-5123](https://bugzilla.mozilla.org/show_bug.cgi?id=CVE-2018-5123).