Bugzilla 2.23.3 through 2.22.7, 3.0.x through 3.3.x, 3.4.x before 3.4.12, 3.5.x, 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.3 allows remote attackers to determine the existence of private group names via a crafted parameter during (1) bug creation or (2) bug editing.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.osvdb.org/74298 | vdb entry |
http://secunia.com/advisories/45501 | third party advisory vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/69034 | vdb entry |
http://www.bugzilla.org/security/3.4.11/ | vendor advisory |
https://bugzilla.mozilla.org/show_bug.cgi?id=653477 | patch |
http://www.osvdb.org/74299 | vdb entry |
http://www.debian.org/security/2011/dsa-2322 | vendor advisory |
http://www.securityfocus.com/bid/49042 | vdb entry |