CVE-2003-1044Mozilla Bugzilla vulnerability

3 documents3 sources
Severity
7.5HIGHNVD
EPSS
0.7%
top 27.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 18
Latest updateApr 29

Description

editproducts.cgi in Bugzilla 2.16.3 and earlier, when usebuggroups is enabled, does not properly remove group add privileges from a group that is being deleted, which allows users with those privileges to perform unauthorized additions to the next group that is assigned with the original group ID.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

NVDmozilla/bugzilla18 versions+17

Patches

🔴Vulnerability Details

2
GHSA
GHSA-vmm3-5p86-6vg7: editproducts2022-04-29
CVEList
CVE-2003-1044: editproducts2004-06-03
CVE-2003-1044 — Mozilla Bugzilla vulnerability | cvebase