CVE-2009-0483
published 2009-02-09CVE-2009-0483: Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.22 before 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote…
PriorityP420medium5.8CVSS 2.0
AVNACMAuNCNIPAP
EPSS
0.60%
45.1th percentile
Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.22 before 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delete keywords and user preferences via a link or IMG tag to (1) editkeywords.cgi or (2) userprefs.cgi.
Affected
69 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4pwx-p54m-78g5: Cross-site request forgery (CSRF) vulnerability in Bugzilla 2
ghsa_unreviewed·2022-05-02
CVE-2009-0483 [MEDIUM] CWE-352 GHSA-4pwx-p54m-78g5: Cross-site request forgery (CSRF) vulnerability in Bugzilla 2
Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.22 before 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delete keywords and user preferences via a link or IMG tag to (1) editkeywords.cgi or (2) userprefs.cgi.
Red Hat
bugzilla: CSRF vuln via editkeywords.cgi and userprefs.cgi
vendor_redhat·2009-02-09·CVSS 5.8
CVE-2009-0483 [MEDIUM] CWE-352 bugzilla: CSRF vuln via editkeywords.cgi and userprefs.cgi
bugzilla: CSRF vuln via editkeywords.cgi and userprefs.cgi
Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.22 before 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delete keywords and user preferences via a link or IMG tag to (1) editkeywords.cgi or (2) userprefs.cgi.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-0483 bugzilla: CSRF vuln via editkeywords.cgi and userprefs.cgi
bugzilla·2009-02-10·CVSS 5.8
CVE-2009-0483 [MEDIUM] CVE-2009-0483 bugzilla: CSRF vuln via editkeywords.cgi and userprefs.cgi
CVE-2009-0483 bugzilla: CSRF vuln via editkeywords.cgi and userprefs.cgi
Name: CVE-2009-0483
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0483
Assigned: 20090209
Reference: CONFIRM: http://www.bugzilla.org/security/2.22.6/
Reference: CONFIRM: https://bugzilla.mozilla.org/show_bug.cgi?id=466692
Reference: CONFIRM: https://bugzilla.mozilla.org/show_bug.cgi?id=472362
Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.22
before 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before
3.3.2 allows remote attackers to delete keywords and user preferences
via a link or IMG tag to (1) editkeywords.cgi or (2) userprefs.cgi.
Discussion:
bugzilla-3.2.2-2.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/bugzilla-3.2.2-2.fc9
---
Bugzilla
CVE-2008-4437 CVE-2008-6098, CVE-2009-048[13456] bugzilla: multiple issues [F9]
bugzilla·2009-02-09·CVSS 7.1
CVE-2008-4437 [HIGH] CVE-2008-4437 CVE-2008-6098, CVE-2009-048[13456] bugzilla: multiple issues [F9]
CVE-2008-4437 CVE-2008-6098, CVE-2009-048[13456] bugzilla: multiple issues [F9]
F9 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
You can eventually use the following link to create the update request:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&release=Fedora%209&bugs=484757,
---
Correct update submission URL is:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&bugs=484757,CVE-2008-6098,CVE-2009-0481,CVE-2009-0482,CVE-2009-0483,CVE-2009-0484,CVE-2009-0485,CVE-2009-0486
---
*** Bug 465958 has been marked as a duplicate of this bug. ***
---
CVE-2008-4437 fixed in upstream 3.0.5 is still unfixed too, adding it to this tracking bug, u
Bugzilla
CVE-2008-4437 CVE-2008-6098, CVE-2009-048[13456] bugzilla: multiple issues [F10]
bugzilla·2009-02-09·CVSS 7.1
CVE-2008-4437 [HIGH] CVE-2008-4437 CVE-2008-6098, CVE-2009-048[13456] bugzilla: multiple issues [F10]
CVE-2008-4437 CVE-2008-6098, CVE-2009-048[13456] bugzilla: multiple issues [F10]
F10 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
You can eventually use the following link to create the update request:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&release=Fedora%2010&bugs=484756,
---
Correct update submission URL is:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&bugs=484756,CVE-2008-6098,CVE-2009-0481,CVE-2009-0482,CVE-2009-0483,CVE-2009-0484,CVE-2009-0485,CVE-2009-0486
---
*** Bug 465959 has been marked as a duplicate of this bug. ***
---
CVE-2008-4437 fixed in upstream 3.0.5 is still unfixed too, adding it to this tracking bug
http://secunia.com/advisories/34361http://www.bugzilla.org/security/2.22.6/http://www.securityfocus.com/bid/33580https://bugzilla.mozilla.org/show_bug.cgi?id=466692https://bugzilla.mozilla.org/show_bug.cgi?id=472362https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00664.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00687.htmlhttp://secunia.com/advisories/34361http://www.bugzilla.org/security/2.22.6/http://www.securityfocus.com/bid/33580https://bugzilla.mozilla.org/show_bug.cgi?id=466692https://bugzilla.mozilla.org/show_bug.cgi?id=472362https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00664.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00687.html
2009-02-09
Published