CVE-2014-1572
published 2014-10-13CVE-2014-1572: The confirm_create_account function in the account-creation feature in token.cgi in Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11…
PriorityP430medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
1.84%
76.6th percentile
The confirm_create_account function in the account-creation feature in token.cgi in Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not specify a scalar context for the realname parameter, which allows remote attackers to create accounts with unverified e-mail addresses by sending three realname values with realname=login_name as the second, as demonstrated by selecting an e-mail address with a domain name for which group privileges are automatically granted.
Affected
198 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | ikiwiki | < ikiwiki 3.20161229 (bookworm) | ikiwiki 3.20161229 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| ikiwiki | ikiwiki | < 3.20161229 | 3.20161229 |
| ikiwiki | ikiwiki | — | — |
| ikiwiki | ikiwiki | — | — |
| ikiwiki | ikiwiki | >= 0 < 3.20161229 | 3.20161229 |
| ikiwiki | ikiwiki | >= 0 < 3.20161229 | 3.20161229 |
| ikiwiki | ikiwiki | >= 0 < 3.20161229 | 3.20161229 |
| ikiwiki | ikiwiki | >= 0 < 3.20161229 | 3.20161229 |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2m62-r3gq-8m9j: The confirm_create_account function in the account-creation feature in token
ghsa_unreviewed·2022-05-17
CVE-2014-1572 [MEDIUM] GHSA-2m62-r3gq-8m9j: The confirm_create_account function in the account-creation feature in token
The confirm_create_account function in the account-creation feature in token.cgi in Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not specify a scalar context for the realname parameter, which allows remote attackers to create accounts with unverified e-mail addresses by sending three realname values with realname=login_name as the second, as demonstrated by selecting an e-mail address with a domain name for which group privileges are automatically granted.
GHSA
GHSA-fvvm-x83v-fc5r: ikiwiki before 3
ghsa_unreviewed·2022-05-14·CVSS 5.0
CVE-2016-9646 [MEDIUM] CWE-287 GHSA-fvvm-x83v-fc5r: ikiwiki before 3
ikiwiki before 3.20161229 incorrectly called the CGI::FormBuilder->field method (similar to the CGI->param API that led to Bugzilla's CVE-2014-1572), which can be abused to lead to commit metadata forgery.
OSV
CVE-2016-9646: ikiwiki before 3
osv·2018-04-13·CVSS 5.0
CVE-2016-9646 [MEDIUM] CVE-2016-9646: ikiwiki before 3
ikiwiki before 3.20161229 incorrectly called the CGI::FormBuilder->field method (similar to the CGI->param API that led to Bugzilla's CVE-2014-1572), which can be abused to lead to commit metadata forgery.
Debian
CVE-2016-9646: ikiwiki - ikiwiki before 3.20161229 incorrectly called the CGI::FormBuilder->field method ...
vendor_debian·2016·CVSS 5.0
CVE-2016-9646 [MEDIUM] CVE-2016-9646: ikiwiki - ikiwiki before 3.20161229 incorrectly called the CGI::FormBuilder->field method ...
ikiwiki before 3.20161229 incorrectly called the CGI::FormBuilder->field method (similar to the CGI->param API that led to Bugzilla's CVE-2014-1572), which can be abused to lead to commit metadata forgery.
Scope: local
bookworm: resolved (fixed in 3.20161229)
bullseye: resolved (fixed in 3.20161229)
forky: resolved (fixed in 3.20161229)
sid: resolved (fixed in 3.20161229)
trixie: resolved (fixed in 3.20161229)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-0356 ikiwiki: Authentication bypass via repeated parameters
bugzilla·2017-01-12·CVSS 5.0
CVE-2017-0356 [MEDIUM] CVE-2017-0356 ikiwiki: Authentication bypass via repeated parameters
CVE-2017-0356 ikiwiki: Authentication bypass via repeated parameters
Security issues were discovered in the passwordauth plugin's use of CGI::FormBuilder, involving API design issues similar to those that led to CVE-2014-1572. Impact:
* An attacker who can log in to a site with a password can log in
as a different and potentially more privileged user.
* An attacker who can create a new account can set arbitrary fields
in the user database for that account.
Sites that enable the CGI script (cgi_wrapper) and do not disable the simple password authentication plugin (passwordauth, enabled by default) are affected.
References:
http://seclists.org/oss-sec/2017/q1/67
https://ikiwiki.info/security/#cve-2017-0356
Discussion:
Created ikiwiki tracking bugs for this issue:
Affects: fedora-all
Bugzilla
CVE-2016-9646 ikiwiki: Commit metadata forgery
bugzilla·2017-01-02·CVSS 5.0
CVE-2016-9646 [MEDIUM] CVE-2016-9646 ikiwiki: Commit metadata forgery
CVE-2016-9646 ikiwiki: Commit metadata forgery
CGI::FormBuilder->field has a context-dependent API, similar to the CGI->param API that led to Bugzilla's CVE-2014-1572. Parts of ikiwiki incorrectly called this method in list context when a scalar result, which could lead to two relatively minor attacks:
In the comments plugin, an attacker who was able to post a comment could give it a user-specified author and author-URL even if the wiki configuration did not allow for that, by crafting multiple values to other fields. Also, in the editpage plugin, an attacker who was able to edit a page could potentially forge commit authorship by crafting multiple values for the rcsinfo field.
References:
http://seclists.org/oss-sec/2016/q4/778
Discussion:
Created ikiwiki tracking bugs for this issu
Bugzilla
[SECURITY] Always use the 3 arguments form for open() to prevent shell code injection
bugzilla·2014-10-07
[MEDIUM] [SECURITY] Always use the 3 arguments form for open() to prevent shell code injection
[SECURITY] Always use the 3 arguments form for open() to prevent shell code injection
User Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; Touch; .NET4.0E; .NET4.0C; Tablet PC 2.0; .NET CLR 3.5.30729; .NET CLR 2.0.50727; .NET CLR 3.0.30729; rv:11.0) like Gecko
Steps to reproduce:
I noticed this during a cursory look through 4.4.6 to examine the other security issues that were fixed.
The filtering of the product name before the 2 arg open in reports.cgi generate_chart() only sanitizes against path traversal attacks. 2 arg open in perl is generally exploitable for shell code injection if the attacker can control the first or last character of the filename. As far as I can tell, an attacker could leverage this input point IF they have enough permissions to control a project name.
Bugzilla
CVE-2014-1573 CVE-2014-1572 CVE-2014-1571 bugzilla: security fixes release [fedora-all]
bugzilla·2014-10-07·CVSS 4.0
CVE-2014-1573 [MEDIUM] CVE-2014-1573 CVE-2014-1572 CVE-2014-1571 bugzilla: security fixes release [fedora-all]
CVE-2014-1573 CVE-2014-1572 CVE-2014-1571 bugzilla: security fixes release [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ve
Bugzilla
CVE-2014-1573 CVE-2014-1572 CVE-2014-1571 bugzilla: security fixes release [epel-all]
bugzilla·2014-10-07·CVSS 4.0
CVE-2014-1573 [MEDIUM] CVE-2014-1573 CVE-2014-1572 CVE-2014-1571 bugzilla: security fixes release [epel-all]
CVE-2014-1573 CVE-2014-1572 CVE-2014-1571 bugzilla: security fixes release [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2014-1571 CVE-2014-1572 CVE-2014-1573 bugzilla: security fixes release
bugzilla·2014-10-07·CVSS 4.0
CVE-2014-1571 [MEDIUM] CVE-2014-1571 CVE-2014-1572 CVE-2014-1573 bugzilla: security fixes release
CVE-2014-1571 CVE-2014-1572 CVE-2014-1573 bugzilla: security fixes release
Upstream has issued an advisory today (October 6):
http://www.bugzilla.org/security/4.0.14/
Class: Unauthorized Account Creation
Versions: 2.23.3 to 4.0.14, 4.1.1 to 4.2.10, 4.3.1 to 4.4.5, 4.5.1 to 4.5.5
Fixed In: 4.0.15, 4.2.11, 4.4.6, 4.5.6
Description: An attacker creating a new Bugzilla account can override certain
parameters when finalizing the account creation that can lead to the
user being created with a different email address than originally
requested. The overridden login name could be automatically added
to groups based on the group's regular expression setting.
References: https://bugzilla.mozilla.org/show_bug.cgi?id=1074812
CVE Number: CVE-2014-1572
Class: Cross-Site Scripting
Versions: 2.17.1 to 4
Bugzilla
[SECURITY] The 'realname' parameter is not correctly filtered on user account creation, leading to user data override
bugzilla·2014-09-30
[CRITICAL] [SECURITY] The 'realname' parameter is not correctly filtered on user account creation, leading to user data override
[SECURITY] The 'realname' parameter is not correctly filtered on user account creation, leading to user data override
User Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2062.120 Safari/537.36
Steps to reproduce:
Hello,
My name is Netanel Rubin, I work as a vulnerability researcher at Check Point Software Technologies.
This is a critical vulnerability report for an issue I discovered in the Bugzilla platform. The successful exploitation of the vulnerability allows the manipulation of any DB field at the user creation procedure, including the 'login_name' field. This breaks the email validation process, and allows an attacker to create accounts which match the groups regex policies, effectively becoming a privileged user.
As a PoC, I've c
http://advisories.mageia.org/MGASA-2014-0412.htmlhttp://blog.gerv.net/2014/10/new-class-of-vulnerability-in-perl-web-applications/http://lists.fedoraproject.org/pipermail/package-announce/2014-November/142524.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-October/141309.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-October/141321.htmlhttp://openwall.com/lists/oss-security/2014/10/07/20http://packetstormsecurity.com/files/128578/Bugzilla-Account-Creation-XSS-Information-Leak.htmlhttp://www.bugzilla.org/security/4.0.14/http://www.mandriva.com/security/advisories?name=MDVSA-2014:200http://www.opennet.ru/opennews/art.shtml?num=40766http://www.reddit.com/r/netsec/comments/2ihen0/new_class_of_vulnerability_in_perl_web/http://www.securitytracker.com/id/1030978https://bugzilla.mozilla.org/show_bug.cgi?id=1074812https://security.gentoo.org/glsa/201607-11http://advisories.mageia.org/MGASA-2014-0412.htmlhttp://blog.gerv.net/2014/10/new-class-of-vulnerability-in-perl-web-applications/http://lists.fedoraproject.org/pipermail/package-announce/2014-November/142524.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-October/141309.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-October/141321.htmlhttp://openwall.com/lists/oss-security/2014/10/07/20http://packetstormsecurity.com/files/128578/Bugzilla-Account-Creation-XSS-Information-Leak.htmlhttp://www.bugzilla.org/security/4.0.14/http://www.mandriva.com/security/advisories?name=MDVSA-2014:200http://www.opennet.ru/opennews/art.shtml?num=40766http://www.reddit.com/r/netsec/comments/2ihen0/new_class_of_vulnerability_in_perl_web/http://www.securitytracker.com/id/1030978https://bugzilla.mozilla.org/show_bug.cgi?id=1074812https://security.gentoo.org/glsa/201607-11
2014-10-13
Published