CVE-2012-4198
published 2012-11-16CVE-2012-4198: The User.get method in Bugzilla/WebService/User.pm in Bugzilla 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1…
PriorityP415medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
0.87%
55.2th percentile
The User.get method in Bugzilla/WebService/User.pm in Bugzilla 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1 has a different outcome for a groups request depending on whether a group exists, which allows remote authenticated users to discover private group names by observing whether a call throws an error.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4hjg-8mv8-5cfh: The User
ghsa_unreviewed·2022-05-17·CVSS 4.0
CVE-2012-5884 [MEDIUM] CWE-200 GHSA-4hjg-8mv8-5cfh: The User
The User.get method in Bugzilla/WebService/User.pm in Bugzilla 4.3.2 allows remote attackers to obtain sensitive information about the saved searches of arbitrary users via an XMLRPC request or a JSONRPC request, a different vulnerability than CVE-2012-4198.
GHSA
GHSA-fcvv-97h9-vfw3: The User
ghsa_unreviewed·2022-05-17
CVE-2012-4198 [MEDIUM] CWE-200 GHSA-fcvv-97h9-vfw3: The User
The User.get method in Bugzilla/WebService/User.pm in Bugzilla 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1 has a different outcome for a groups request depending on whether a group exists, which allows remote authenticated users to discover private group names by observing whether a call throws an error.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.bugzilla.org/security/3.6.11/http://www.mandriva.com/security/advisories?name=MDVSA-2013:066https://bugzilla.mozilla.org/show_bug.cgi?id=781850http://www.bugzilla.org/security/3.6.11/http://www.mandriva.com/security/advisories?name=MDVSA-2013:066https://bugzilla.mozilla.org/show_bug.cgi?id=781850
2012-11-16
Published