CVE-2011-2978Improper Input Validation in Mozilla Bugzilla

Severity
5.0MEDIUMNVD
EPSS
0.7%
top 29.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 9
Latest updateMay 17

Description

Bugzilla 2.16rc1 through 2.22.7, 3.0.x through 3.3.x, 3.4.x before 3.4.12, 3.5.x, 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.3 does not prevent changes to the confirmation e-mail address (aka old_email field) for e-mail change notifications, which makes it easier for remote attackers to perform arbitrary address changes by leveraging an unattended workstation.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDmozilla/bugzilla115 versions+114

Patches

🔴Vulnerability Details

2
GHSA
GHSA-rrm5-5c6m-75m4: Bugzilla 22022-05-17
CVEList
CVE-2011-2978: Bugzilla 22011-08-09

💬Community

2
Bugzilla
CVE-2011-2976 CVE-2011-2379 CVE-2011-2380 CVE-2011-2979 CVE-2011-2381 CVE-2011-2978 CVE-2011-2977 bugzilla: multiple security flaws fixed in 3.4.12, 3.6.6, 4.0.2, and 4.1.3 [epel-all]2011-08-08
Bugzilla
CVE-2011-2976 CVE-2011-2379 CVE-2011-2380 CVE-2011-2979 CVE-2011-2381 CVE-2011-2978 CVE-2011-2977 bugzilla: multiple security flaws fixed in 3.4.12, 3.6.6, 4.0.2, and 4.1.32011-08-08
CVE-2011-2978 — Improper Input Validation in Mozilla | cvebase