CVE-2012-0453
published 2012-02-25CVE-2012-0453: Cross-site request forgery (CSRF) vulnerability in xmlrpc.cgi in Bugzilla 4.0.2 through 4.0.4 and 4.1.1 through 4.2rc2, when mod_perl is used, allows remote…
PriorityP422medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EPSS
0.83%
53.7th percentile
Cross-site request forgery (CSRF) vulnerability in xmlrpc.cgi in Bugzilla 4.0.2 through 4.0.4 and 4.1.1 through 4.2rc2, when mod_perl is used, allows remote attackers to hijack the authentication of arbitrary users for requests that modify the product's installation via the XML-RPC API.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-0453 bugzilla: CSRF fixed in 4.0.5, 4.2
bugzilla·2012-02-24·CVSS 5.1
CVE-2012-0453 [MEDIUM] CVE-2012-0453 bugzilla: CSRF fixed in 4.0.5, 4.2
CVE-2012-0453 bugzilla: CSRF fixed in 4.0.5, 4.2
Upstream has released [1] versions 4.0.5, 4.2 to correct a CSRF vulnerability
Due to a lack of validation of the enctype form attribute when making POST requests to xmlrpc.cgi, a possible CSRF vulnerability was discovered. If a user visits an HTML page with some malicious HTML code in it, an attacker could make changes to a remote Bugzilla installation on behalf of the victim's account by using the XML-RPC API on a site running mod_perl. Sites running under mod_cgi are not affected. Also the user would have had to be already logged in to the target site for the vulnerability to work.
References: https://bugzilla.mozilla.org/show_bug.cgi?id=725663
[1] http://www.bugzilla.org/security/4.0.4/
Discussion:
Created bugzilla tracking bugs for
Bugzilla
CVE-2012-0453 bugzilla: CSRF fixed in 4.0.5, 4.2 [fedora-all]
bugzilla·2012-02-24·CVSS 5.1
CVE-2012-0453 [MEDIUM] CVE-2012-0453 bugzilla: CSRF fixed in 4.0.5, 4.2 [fedora-all]
CVE-2012-0453 bugzilla: CSRF fixed in 4.0.5, 4.2 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=796984
2012-02-25
Published