CVSS2
Attack Vector
NETWORK
Attack Complexity
HIGH
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:H/Au:N/C:P/I:P/A:P
EPSS
Percentile
73.9%
Cross-site request forgery (CSRF) vulnerability in jsonrpc.cgi in Bugzilla
3.5.x and 3.6.x before 3.6.8, 3.7.x and 4.0.x before 4.0.4, and 4.1.x and
4.2.x before 4.2rc2 allows remote attackers to hijack the authentication of
arbitrary users for requests that use the JSON-RPC API.
Author | Note |
---|---|
tyhicks | marking it as low because I donβt think the JSON-RPC API is used much |