Severity
4.3MEDIUMNVD
EPSS
0.7%
top 27.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 28
Latest updateMay 17

Description

Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 does not properly handle whitespace preceding a (1) javascript: or (2) data: URI, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the URL (aka bug_file_loc) field.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDmozilla/bugzilla3.2.9+97

Patches

🔴Vulnerability Details

2
GHSA
GHSA-rvrf-fv66-542r: Bugzilla before 32022-05-17
CVEList
CVE-2010-4567: Bugzilla before 32011-01-28

📋Vendor Advisories

2
Red Hat
kernel: ipv6: skb_dst() can be NULL in ipv6_hop_jumbo()2009-01-14
Red Hat
kernel: ipv6_hop_jumbo remote system crash2007-09-07

💬Community

1
Bugzilla
CVE-2007-4567 kernel: ipv6_hop_jumbo remote system crash2009-12-18
CVE-2010-4567 — Cross-site Scripting in Mozilla | cvebase