Bugzilla before 2.14 allows Bugzilla users to bypass group security checks by marking a bug as the duplicate of a restricted bug, which adds the user to the CC list of the restricted bug and allows the user to view the bug.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2001-09-09 21:00
Updated : 2016-10-17 19:15
NVD link : CVE-2001-1407
Mitre link : CVE-2001-1407
JSON object : View
CWE
Products Affected
mozilla
- bugzilla