CVE-2015-8509
published 2016-01-03CVE-2015-8509: Template.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.16, 4.3.x and 4.4.x before 4.4.11, and 4.5.x and 5.0.x before 5.0.2 does not properly construct CSV files…
PriorityP416low3.5CVSS 3.0
AVNACLPRLUIRSUCLINAN
EPSS
1.91%
77.6th percentile
Template.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.16, 4.3.x and 4.4.x before 4.4.11, and 4.5.x and 5.0.x before 5.0.2 does not properly construct CSV files, which allows remote attackers to obtain sensitive information by leveraging a web browser that interprets CSV data as JavaScript code.
Affected
147 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
CVSS provenance
nvdv3.03.5LOWCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8509 bugzilla: information leak when parsing the CSV file [fedora-all]
bugzilla·2016-01-04·CVSS 3.5
CVE-2015-8509 [LOW] CVE-2015-8509 bugzilla: information leak when parsing the CSV file [fedora-all]
CVE-2015-8509 bugzilla: information leak when parsing the CSV file [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions o
Bugzilla
CVE-2015-8509 bugzilla: information leak when parsing the CSV file
bugzilla·2016-01-04·CVSS 3.5
CVE-2015-8509 [LOW] CVE-2015-8509 bugzilla: information leak when parsing the CSV file
CVE-2015-8509 bugzilla: information leak when parsing the CSV file
Upstream Bugzilla fixed the following issue:
If an external HTML page contains a element with its src attribute pointing to a buglist in CSV format, some web browsers incorrectly try to parse the CSV file as valid JavaScript code. As the buglist is generated based on the privileges of the user logged into Bugzilla, the external page could collect confidential data contained in the CSV file.
This issue was fixed in versions 4.2.16, 4.4.11, and 5.0.2.
Upstream bug:
https://bugzilla.mozilla.org/show_bug.cgi?id=1232785
Discussion:
Created bugzilla tracking bugs for this issue:
Affects: fedora-all [bug 1295439]
---
The update that fixes this issue was published late 2015 (this is update FEDORA-2015-247b517a18, btw). I'
http://packetstormsecurity.com/files/135048/Bugzilla-Cross-Site-Scripting-Information-Leak.htmlhttp://seclists.org/bugtraq/2015/Dec/131http://www.securityfocus.com/bid/79662http://www.securitytracker.com/id/1034556https://bugzilla.mozilla.org/show_bug.cgi?id=1232785https://www.bugzilla.org/security/4.2.15/http://packetstormsecurity.com/files/135048/Bugzilla-Cross-Site-Scripting-Information-Leak.htmlhttp://seclists.org/bugtraq/2015/Dec/131http://www.securityfocus.com/bid/79662http://www.securitytracker.com/id/1034556https://bugzilla.mozilla.org/show_bug.cgi?id=1232785https://www.bugzilla.org/security/4.2.15/
2016-01-03
Published