CVE-2009-3386Sensitive Information Exposure in Mozilla Bugzilla

Severity
5.0MEDIUMNVD
EPSS
0.7%
top 29.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 20
Latest updateJun 18

Description

Template.pm in Bugzilla 3.3.2 through 3.4.3 and 3.5 through 3.5.1 allows remote attackers to discover the alias of a private bug by reading the (1) Depends On or (2) Blocks field of a related bug.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDmozilla/bugzilla9 versions+8

Patches

🔴Vulnerability Details

2
GHSA
GHSA-xf88-gp54-xgc2: Template2022-05-02
CVEList
CVE-2009-3386: Template2009-11-20

📋Vendor Advisories

2
Red Hat
kernel: KVM: SVM: Don't BUG if userspace injects an interrupt with GIF=02025-06-18
Red Hat
bugzilla hidden bug alias disclosure2009-11-18

💬Community

7
Bugzilla
CVE-2009-3386 bugzilla hidden bug alias disclosure2009-11-20
Bugzilla
CVE-2009-3386 bugzilla hidden bug alias disclosure [Fdevel]2009-11-20
Bugzilla
CVE-2009-3386 bugzilla hidden bug alias disclosure [F11]2009-11-20
Bugzilla
CVE-2009-3386 bugzilla hidden bug alias disclosure [F12]2009-11-20
Bugzilla
CVE-2009-3014 firefox/seamonkey: XSS via improper handling of javascript: URIs in certain HTML links2009-08-31
CVE-2009-3386 — Sensitive Information Exposure | cvebase