CVE-2013-1734
published 2013-10-24CVE-2013-1734: Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 2.x, 3.x, and 4.0.x before 4.0.11; 4.1.x and 4.2.x before 4.2.7; and 4.3.x and…
PriorityP427medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
0.58%
44.2th percentile
Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 2.x, 3.x, and 4.0.x before 4.0.11; 4.1.x and 4.2.x before 4.2.7; and 4.3.x and 4.4.x before 4.4.1 allows remote attackers to hijack the authentication of arbitrary users for requests that commit an attachment change via an update action.
Affected
170 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1734 CVE-2013-1743 CVE-2013-1742 bugzilla: multiple flaws corrected in upstream 4.0.11, 4.2.7, 4.4.1 [fedora-all]
bugzilla·2013-10-17·CVSS 6.8
CVE-2013-1734 [MEDIUM] CVE-2013-1734 CVE-2013-1743 CVE-2013-1742 bugzilla: multiple flaws corrected in upstream 4.0.11, 4.2.7, 4.4.1 [fedora-all]
CVE-2013-1734 CVE-2013-1743 CVE-2013-1742 bugzilla: multiple flaws corrected in upstream 4.0.11, 4.2.7, 4.4.1 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field
Bugzilla
CVE-2013-1734 CVE-2013-1742 CVE-2013-1743 bugzilla: multiple flaws corrected in upstream 4.0.11, 4.2.7, 4.4.1
bugzilla·2013-10-17·CVSS 4.3
CVE-2013-1734 [MEDIUM] CVE-2013-1734 CVE-2013-1742 CVE-2013-1743 bugzilla: multiple flaws corrected in upstream 4.0.11, 4.2.7, 4.4.1
CVE-2013-1734 CVE-2013-1742 CVE-2013-1743 bugzilla: multiple flaws corrected in upstream 4.0.11, 4.2.7, 4.4.1
A number of flaws were reported in Bugzilla [1]:
Class: Cross-Site Request Forgery
Versions: 2.16rc1 to 4.0.10, 4.1.1 to 4.2.6, 4.3.1 to 4.4
Fixed In: 4.0.11, 4.2.7, 4.4.1
Description: When an attachment is edited, a token is generated to
validate changes made by the user. Using a crafted URL,
an attacker could force the token to be recreated,
allowing him to bypass the token check and abuse a user
to commit changes on his behalf.
References: https://bugzilla.mozilla.org/show_bug.cgi?id=913904
CVE Number: CVE-2013-1734
Class: Cross-Site Scripting
Versions: 2.17.1 to 4.0.10, 4.1.1 to 4.2.6, 4.3.1 to 4.4
Fixed In: 4.0.11, 4.2.7, 4.4.1
Description: Some parameters passed to editf
Bugzilla
CVE-2013-1734 CVE-2013-1743 CVE-2013-1742 bugzilla: multiple flaws corrected in upstream 4.0.11, 4.2.7, 4.4.1 [epel-all]
bugzilla·2013-10-17·CVSS 6.8
CVE-2013-1734 [MEDIUM] CVE-2013-1734 CVE-2013-1743 CVE-2013-1742 bugzilla: multiple flaws corrected in upstream 4.0.11, 4.2.7, 4.4.1 [epel-all]
CVE-2013-1734 CVE-2013-1743 CVE-2013-1742 bugzilla: multiple flaws corrected in upstream 4.0.11, 4.2.7, 4.4.1 [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes fi
Bugzilla
[SECURITY] CSRF when updating attachments
bugzilla·2013-09-08·CVSS 6.8
[MEDIUM] [SECURITY] CSRF when updating attachments
[SECURITY] CSRF when updating attachments
PoC:
Discussion:
Created attachment 801238
patch for 4.4 and trunk, v1
This patch is similar to the one for process_bug.cgi.
---
All versions are affected as bug 476603 was an incomplete fix.
---
Created attachment 801248
patch for 4.2, v1
---
Created attachment 801251
patch for 4.0, v1
I had to backport the invalid_timestamp error message which didn't exist before 4.2.
---
Use CVE-2013-1734
Why sec-critical? This isn't compromising bugzilla in general. Beyond vandalism what's the worst you could do here? Luring a privileged user to un-hide an attachment maybe, revealing a security bug? My initial feel was moderate, but given hidden attachments I could live with sec-high.
---
Comment on attachment 801238
patc
2013-10-24
Published