CVE-2010-3764Sensitive Information Exposure in Mozilla Bugzilla

Severity
5.0MEDIUMNVD
EPSS
0.8%
top 25.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 5
Latest updateMay 17

Description

The Old Charts implementation in Bugzilla 2.12 through 3.2.8, 3.4.8, 3.6.2, 3.7.3, and 4.1 creates graph files with predictable names in graphs/, which allows remote attackers to obtain sensitive information via a modified URL.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDmozilla/bugzilla84 versions+83

Patches

🔴Vulnerability Details

2
GHSA
GHSA-v9g4-4g73-5g38: The Old Charts implementation in Bugzilla 22022-05-17
CVEList
CVE-2010-3764: The Old Charts implementation in Bugzilla 22010-11-05

💬Community

2
Bugzilla
CVE-2010-3764 bugzilla: information leak via Old Charts system2010-11-03
Bugzilla
CVE-2010-3172 CVE-2010-3764 bugzilla various flaws [fedora-all]2010-11-03
CVE-2010-3764 — Sensitive Information Exposure | cvebase