CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
SINGLE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:S/C:P/I:P/A:P
AI Score
Confidence
Low
EPSS
Percentile
65.7%
The sudo feature in Bugzilla 2.22rc1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 does not properly send impersonation notifications, which makes it easier for remote authenticated users to impersonate other users without discovery.
Vendor | Product | Version | CPE |
---|---|---|---|
mozilla | bugzilla | 2.4 | cpe:2.3:a:mozilla:bugzilla:2.4:*:*:*:*:*:*:* |
mozilla | bugzilla | 2.6 | cpe:2.3:a:mozilla:bugzilla:2.6:*:*:*:*:*:*:* |
mozilla | bugzilla | 2.8 | cpe:2.3:a:mozilla:bugzilla:2.8:*:*:*:*:*:*:* |
mozilla | bugzilla | 2.9 | cpe:2.3:a:mozilla:bugzilla:2.9:*:*:*:*:*:*:* |
mozilla | bugzilla | 2.22 | cpe:2.3:a:mozilla:bugzilla:2.22:*:*:*:*:*:*:* |
mozilla | bugzilla | 2.22 | cpe:2.3:a:mozilla:bugzilla:2.22:rc1:*:*:*:*:*:* |
mozilla | bugzilla | 2.22.1 | cpe:2.3:a:mozilla:bugzilla:2.22.1:*:*:*:*:*:*:* |
mozilla | bugzilla | 2.22.3 | cpe:2.3:a:mozilla:bugzilla:2.22.3:*:*:*:*:*:*:* |
mozilla | bugzilla | 2.22.4 | cpe:2.3:a:mozilla:bugzilla:2.22.4:*:*:*:*:*:*:* |
mozilla | bugzilla | 2.22.5 | cpe:2.3:a:mozilla:bugzilla:2.22.5:*:*:*:*:*:*:* |
lists.fedoraproject.org/pipermail/package-announce/2010-August/046518.html
lists.fedoraproject.org/pipermail/package-announce/2010-August/046534.html
lists.fedoraproject.org/pipermail/package-announce/2010-August/046546.html
secunia.com/advisories/40892
secunia.com/advisories/41128
www.bugzilla.org/security/3.2.7/
www.securityfocus.com/bid/42275
www.vupen.com/english/advisories/2010/2035
www.vupen.com/english/advisories/2010/2205
bugzilla.mozilla.org/show_bug.cgi?id=450013
bugzilla.redhat.com/show_bug.cgi?id=623423