Total vulnerabilities in the database
The WebService (XML-RPC) interface in Bugzilla 2.23.3 through 3.0.0 does not enforce permissions for the time-tracking fields of bugs, which allows remote attackers to obtain sensitive information via certain XML-RPC requests, as demonstrated by the (1) Deadline and (2) Estimated Time fields.
Software | From | Fixed in |
---|---|---|
mozilla / bugzilla | 3.0.0 | 3.0.0.x |
mozilla / bugzilla | 2.23.4 | 2.23.4.x |
mozilla / bugzilla | 2.23.3 | 2.23.3.x |
mozilla / bugzilla | 2.6 | 2.6.x |
mozilla / bugzilla | 2.4 | 2.4.x |
mozilla / bugzilla | 2.8 | 2.8.x |
mozilla / bugzilla | 2.9 | 2.9.x |