CVE-2009-3989
published 2010-02-03CVE-2009-3989: Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.53%
72.1th percentile
Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt.
Affected
77 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | bugzilla | <= 3.0.10 | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Mozilla Bugzilla up to 3.5.1 Installation access control (Bug 434801 / Nessus ID 44426)
vuldb·2026-04-30·CVSS 4.3
CVE-2009-3989 [MEDIUM] Mozilla Bugzilla up to 3.5.1 Installation access control (Bug 434801 / Nessus ID 44426)
A vulnerability, which was classified as problematic, has been found in Mozilla Bugzilla up to 3.5.1. This impacts an unknown function of the component Installation. The manipulation leads to improper access controls.
This vulnerability is documented as CVE-2009-3989. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
GHSA
GHSA-gvr3-v3rm-vjm4: Bugzilla before 3
ghsa_unreviewed·2022-05-02
CVE-2009-3989 [MEDIUM] GHSA-gvr3-v3rm-vjm4: Bugzilla before 3
Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt.
Red Hat
bugzilla: Sensitive information disclosure via various attack vectors
vendor_redhat·2005-11-02·CVSS 4.3
CVE-2009-3989 [MEDIUM] bugzilla: Sensitive information disclosure via various attack vectors
bugzilla: Sensitive information disclosure via various attack vectors
Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/38443http://www.securityfocus.com/archive/1/509282/100/0/threadedhttp://www.securityfocus.com/bid/38025http://www.vupen.com/english/advisories/2010/0261https://bugzilla.mozilla.org/show_bug.cgi?id=314871https://bugzilla.mozilla.org/show_bug.cgi?id=434801https://exchange.xforce.ibmcloud.com/vulnerabilities/56003http://secunia.com/advisories/38443http://www.securityfocus.com/archive/1/509282/100/0/threadedhttp://www.securityfocus.com/bid/38025http://www.vupen.com/english/advisories/2010/0261https://bugzilla.mozilla.org/show_bug.cgi?id=314871https://bugzilla.mozilla.org/show_bug.cgi?id=434801https://exchange.xforce.ibmcloud.com/vulnerabilities/56003
2010-02-03
Published