CVE-2001-1406Mozilla Bugzilla vulnerability

5 documents5 sources
Severity
2.1LOWNVD
EPSS
0.2%
top 56.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 10
Latest updateApr 30

Description

process_bug.cgi in Bugzilla before 2.14 does not set the "groupset" bit when a bug is moved between product groups, which will cause the bug to have the old group's restrictions, which might not be as stringent.

CVSS vector

AV:L/AC:L/C:P/I:N/A:NExploitability: 3.9 | Impact: 2.9

Affected Packages1 packages

NVDmozilla/bugzilla6 versions+5

Patches

🔴Vulnerability Details

2
GHSA
GHSA-fq54-7wqq-xmv8: process_bug2022-04-30
CVEList
CVE-2001-1406: process_bug2003-04-02

📋Vendor Advisories

1
Red Hat
security flaw2001-08-29

💬Community

1
Bugzilla
CVE-2001-1406 security flaw2018-08-16