CVE-2009-3387
published 2010-02-03CVE-2009-3387: Bugzilla 3.3.1 through 3.4.4, 3.5.1, and 3.5.2 does not allow group restrictions to be preserved throughout the process of moving a bug to a different product…
PriorityP421medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.70%
74.8th percentile
Bugzilla 3.3.1 through 3.4.4, 3.5.1, and 3.5.2 does not allow group restrictions to be preserved throughout the process of moving a bug to a different product category, which allows remote attackers to obtain sensitive information via a request for a bug in opportunistic circumstances.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Mozilla Bugzilla up to 3.5.2 access control (Nessus ID 44346 / ID 116895)
vuldb·2026-04-30·CVSS 5.0
CVE-2009-3387 [MEDIUM] Mozilla Bugzilla up to 3.5.2 access control (Nessus ID 44346 / ID 116895)
A vulnerability classified as problematic was found in Mozilla Bugzilla up to 3.5.2. This affects an unknown function. Executing a manipulation can lead to improper access controls.
This vulnerability is registered as CVE-2009-3387. It is possible to launch the attack remotely. No exploit is available.
GHSA
GHSA-24h9-wwcg-r638: Bugzilla 3
ghsa_unreviewed·2022-05-02
CVE-2009-3387 [MEDIUM] GHSA-24h9-wwcg-r638: Bugzilla 3
Bugzilla 3.3.1 through 3.4.4, 3.5.1, and 3.5.2 does not allow group restrictions to be preserved throughout the process of moving a bug to a different product category, which allows remote attackers to obtain sensitive information via a request for a bug in opportunistic circumstances.
Red Hat
bugzilla: Sensitive information disclosure via various attack vectors
vendor_redhat·2005-11-02·CVSS 5.0
CVE-2009-3387 [MEDIUM] bugzilla: Sensitive information disclosure via various attack vectors
bugzilla: Sensitive information disclosure via various attack vectors
Bugzilla 3.3.1 through 3.4.4, 3.5.1, and 3.5.2 does not allow group restrictions to be preserved throughout the process of moving a bug to a different product category, which allows remote attackers to obtain sensitive information via a request for a bug in opportunistic circumstances.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/38443http://www.securityfocus.com/archive/1/509282/100/0/threadedhttp://www.securityfocus.com/bid/38026http://www.vupen.com/english/advisories/2010/0261https://bugzilla.mozilla.org/show_bug.cgi?id=532493https://exchange.xforce.ibmcloud.com/vulnerabilities/56004http://secunia.com/advisories/38443http://www.securityfocus.com/archive/1/509282/100/0/threadedhttp://www.securityfocus.com/bid/38026http://www.vupen.com/english/advisories/2010/0261https://bugzilla.mozilla.org/show_bug.cgi?id=532493https://exchange.xforce.ibmcloud.com/vulnerabilities/56004
2010-02-03
Published