CVE-2009-0482
published 2009-02-09CVE-2009-0482: Cross-site request forgery (CSRF) vulnerability in Bugzilla before 3.2 before 3.2.1, 3.3 before 3.3.2, and other versions before 3.2 allows remote attackers to…
PriorityP420medium5.8CVSS 2.0
AVNACMAuNCNIPAP
EPSS
0.50%
40.1th percentile
Cross-site request forgery (CSRF) vulnerability in Bugzilla before 3.2 before 3.2.1, 3.3 before 3.3.2, and other versions before 3.2 allows remote attackers to perform bug updating activities as other users via a link or IMG tag to process_bug.cgi.
Affected
69 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
bugzilla: CSRF vuln via process_bug.cgi
vendor_redhat·2009-02-09·CVSS 5.8
CVE-2009-0482 [MEDIUM] CWE-352 bugzilla: CSRF vuln via process_bug.cgi
bugzilla: CSRF vuln via process_bug.cgi
Cross-site request forgery (CSRF) vulnerability in Bugzilla before 3.2 before 3.2.1, 3.3 before 3.3.2, and other versions before 3.2 allows remote attackers to perform bug updating activities as other users via a link or IMG tag to process_bug.cgi.
GHSA
GHSA-q7v7-wgvv-h4x9: Cross-site request forgery (CSRF) vulnerability in Bugzilla before 3
ghsa_unreviewed·2022-05-02
CVE-2009-0482 [MEDIUM] CWE-352 GHSA-q7v7-wgvv-h4x9: Cross-site request forgery (CSRF) vulnerability in Bugzilla before 3
Cross-site request forgery (CSRF) vulnerability in Bugzilla before 3.2 before 3.2.1, 3.3 before 3.3.2, and other versions before 3.2 allows remote attackers to perform bug updating activities as other users via a link or IMG tag to process_bug.cgi.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-0482 bugzilla: CSRF vuln via process_bug.cgi
bugzilla·2009-02-10·CVSS 5.8
CVE-2009-0482 [MEDIUM] CVE-2009-0482 bugzilla: CSRF vuln via process_bug.cgi
CVE-2009-0482 bugzilla: CSRF vuln via process_bug.cgi
Name: CVE-2009-0482
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0482
Assigned: 20090209
Reference: CONFIRM: http://www.bugzilla.org/security/2.22.6/
Cross-site request forgery (CSRF) vulnerability in Bugzilla before 3.2
before 3.2.1, 3.3 before 3.3.2, and other versions before 3.2 allows
remote attackers to perform bug updating activities as other users via
a link or IMG tag to process_bug.cgi.
Discussion:
Fixed via:
https://admin.fedoraproject.org/updates/F10/FEDORA-2009-2417
https://admin.fedoraproject.org/updates/F10/FEDORA-2009-2418
---
bugzilla-3.2.2-2.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
---
bugzilla-3.2.2-2.fc10 has be
Bugzilla
CVE-2008-4437 CVE-2008-6098, CVE-2009-048[13456] bugzilla: multiple issues [F9]
bugzilla·2009-02-09·CVSS 7.1
CVE-2008-4437 [HIGH] CVE-2008-4437 CVE-2008-6098, CVE-2009-048[13456] bugzilla: multiple issues [F9]
CVE-2008-4437 CVE-2008-6098, CVE-2009-048[13456] bugzilla: multiple issues [F9]
F9 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
You can eventually use the following link to create the update request:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&release=Fedora%209&bugs=484757,
---
Correct update submission URL is:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&bugs=484757,CVE-2008-6098,CVE-2009-0481,CVE-2009-0482,CVE-2009-0483,CVE-2009-0484,CVE-2009-0485,CVE-2009-0486
---
*** Bug 465958 has been marked as a duplicate of this bug. ***
---
CVE-2008-4437 fixed in upstream 3.0.5 is still unfixed too, adding it to this tracking bug, u
Bugzilla
CVE-2008-4437 CVE-2008-6098 CVE-2008-048[13456] bugzilla: multiple issues [Fdevel]
bugzilla·2009-02-09·CVSS 7.1
CVE-2008-4437 [HIGH] CVE-2008-4437 CVE-2008-6098 CVE-2008-048[13456] bugzilla: multiple issues [Fdevel]
CVE-2008-4437 CVE-2008-6098 CVE-2008-048[13456] bugzilla: multiple issues [Fdevel]
Fdevel tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
Adding also CVE-2008-4437, which was upstream in 3.0.5.
---
This package has changed ownership in the Fedora Package Database. Reassigning to the new owner of this component.
---
I am going upgrade to 3.0.8 in F-10 and F-9 and to 3.2.2 into rawhide.
*** This bug has been marked as a duplicate of bug 474250 ***
---
CVE-2009-0482 was not fixed upstream in 3.0.x
---
going to 3.2.2 soon
Bugzilla
CVE-2008-4437 CVE-2008-6098, CVE-2009-048[13456] bugzilla: multiple issues [F10]
bugzilla·2009-02-09·CVSS 7.1
CVE-2008-4437 [HIGH] CVE-2008-4437 CVE-2008-6098, CVE-2009-048[13456] bugzilla: multiple issues [F10]
CVE-2008-4437 CVE-2008-6098, CVE-2009-048[13456] bugzilla: multiple issues [F10]
F10 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
You can eventually use the following link to create the update request:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&release=Fedora%2010&bugs=484756,
---
Correct update submission URL is:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&bugs=484756,CVE-2008-6098,CVE-2009-0481,CVE-2009-0482,CVE-2009-0483,CVE-2009-0484,CVE-2009-0485,CVE-2009-0486
---
*** Bug 465959 has been marked as a duplicate of this bug. ***
---
CVE-2008-4437 fixed in upstream 3.0.5 is still unfixed too, adding it to this tracking bug
http://secunia.com/advisories/34361http://www.bugzilla.org/security/2.22.6/http://www.securityfocus.com/bid/33580https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00664.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00687.htmlhttp://secunia.com/advisories/34361http://www.bugzilla.org/security/2.22.6/http://www.securityfocus.com/bid/33580https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00664.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00687.html
2009-02-09
Published