CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
Percentile
42.2%
The Flag::validate and Flag::modify functions in Bugzilla 2.17.1 to 2.18.1
and 2.19.1 to 2.19.3 do not verify that the flag ID is appropriate for the
given bug or attachment ID, which allows users to change flags on arbitrary
bugs and obtain a bug summary via process_bug.cgi.