VDB

GCVE-110-MAGEIA-2014-200

GCVE-110-MAGEIA-2014-200
Advisory Published
Vulnetix · Advisory published May 2, 2014
Updated bugzilla packages fix security vulnerability: The login form in Bugzilla 2.x, 3.x, 4.x before 4.4.3, and 4.5.x before 4.5.3 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account and then submit a vulnerability report, related to a "login CSRF" issue (CVE-2014-1517).

Affected Products

VendorProductVersionsPlatforms
Mageiabugzilla0 (affected), 4.4.4-1.1.mga4 (unaffected), 0 (affected), 4.4.4-1.1.mga4 (unaffected)
Mageiaseahorse0 (affected), 3.10.2-1.mga4 (unaffected)

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›