CVE-2014-1517 PUBLISHED CVSS 4 MEDIUM

The login form in Bugzilla 2.x, 3.x, 4.x before 4.4.3, and 4.5.x before 4.5.3 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account and then submit a vulnerability report, related to a "login CSRF" issue.

EPSS 0.39% · 60.1th percentile

Risk Scores

CVSS v2.0
4
EPSS Score
0.39%
60.1th percentile

Affected Products

VendorProductVersions
n/an/an/a
mozillabugzilla2.0, 2.2, 2.4
fedoraprojectfedora19, 20

Timeline

References

Open in Interactive Console →