CVE-2002-0007Mozilla Bugzilla vulnerability

5 documents5 sources
Severity
10.0CRITICALNVD
EPSS
2.2%
top 15.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 31
Latest updateApr 30

Description

CGI.pl in Bugzilla before 2.14.1, when using LDAP, allows remote attackers to obtain an anonymous bind to the LDAP server via a request that does not include a password, which causes a null password to be sent to the LDAP server.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages1 packages

NVDmozilla/bugzilla2.14.1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-xmjv-5hmh-hg5p: CGI2022-04-30
CVEList
CVE-2002-0007: CGI2002-06-25

📋Vendor Advisories

1
Red Hat
security flaw2002-01-05

💬Community

1
Bugzilla
CVE-2002-0007 security flaw2018-08-16
CVE-2002-0007 — Mozilla Bugzilla vulnerability | cvebase