Search.pm in Bugzilla 2.19.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 allows remote attackers to determine the group memberships of arbitrary users via vectors involving the Search interface, boolean charts, and group-based pronouns.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2010-08-16 08:14
Updated : 2010-09-07 22:48
NVD link : CVE-2010-2756
Mitre link : CVE-2010-2756
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
mozilla
- bugzilla