CVE-2014-1546
published 2014-08-14CVE-2014-1546: The response function in the JSONP endpoint in WebService/Server/JSONRPC.pm in jsonrpc.cgi in Bugzilla 3.x and 4.x before 4.0.14, 4.1.x and 4.2.x before…
PriorityP415medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
0.54%
42.3th percentile
The response function in the JSONP endpoint in WebService/Server/JSONRPC.pm in jsonrpc.cgi in Bugzilla 3.x and 4.x before 4.0.14, 4.1.x and 4.2.x before 4.2.10, 4.3.x and 4.4.x before 4.4.5, and 4.5.x before 4.5.5 accepts certain long callback values and does not restrict the initial bytes of a JSONP response, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and obtain sensitive information, via a crafted OBJECT element with SWF content consistent with the _bz_callback character set.
Affected
113 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Bugzilla
CVE-2014-1546 bugzilla: Cross Site Request Forgery issue with Bugzilla's JSONP endpoint
bugzilla·2014-07-25·CVSS 4.3
CVE-2014-1546 [MEDIUM] CVE-2014-1546 bugzilla: Cross Site Request Forgery issue with Bugzilla's JSONP endpoint
CVE-2014-1546 bugzilla: Cross Site Request Forgery issue with Bugzilla's JSONP endpoint
The upstream Bugzilla 4.0.14, 4.2.10, 4.4.5, 4.5.5 releases fix the following issue:
""
Adobe does not properly restrict the SWF file format,
which allows remote attackers to conduct cross-site
request forgery (CSRF) attacks against Bugzilla's JSONP
endpoint, possibly obtaining sensitive bug information,
via a crafted OBJECT element with SWF content satisfying
the character-set requirements of a callback API.
References: https://bugzilla.mozilla.org/show_bug.cgi?id=1036213
""
The 3.2.10 and 3.4.14 versions in EPEL 5 and 6 appear too old to be affected.
Reference:
http://www.bugzilla.org/security/4.0.13/
Discussion:
Created bugzilla tracking bugs for this issue:
Affects: fedora-all [bug 1123173]
Bugzilla
CVE-2014-1546 bugzilla: Cross Site Request Forgery issue with Bugzilla's JSONP endpoint [fedora-all]
bugzilla·2014-07-25·CVSS 4.3
CVE-2014-1546 [MEDIUM] CVE-2014-1546 bugzilla: Cross Site Request Forgery issue with Bugzilla's JSONP endpoint [fedora-all]
CVE-2014-1546 bugzilla: Cross Site Request Forgery issue with Bugzilla's JSONP endpoint [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
http://advisories.mageia.org/MGASA-2014-0349.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-August/136217.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-August/136369.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2014:169http://www.securityfocus.com/archive/1/532895http://www.securitytracker.com/id/1030648https://bugzilla.mozilla.org/show_bug.cgi?id=1036213http://advisories.mageia.org/MGASA-2014-0349.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-August/136217.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-August/136369.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2014:169http://www.securityfocus.com/archive/1/532895http://www.securitytracker.com/id/1030648https://bugzilla.mozilla.org/show_bug.cgi?id=1036213
2014-08-14
Published