Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mhp7-wjrm-g66r

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Flag::validate and Flag::modify functions in Bugzilla 2.17.1 to 2.18.1 and 2.19.1 to 2.19.3 do not verify that the flag ID is appropriate for the given bug or attachment ID, which allows users to change flags on arbitrary bugs and obtain a bug summary via process_bug.cgi.

The Flag::validate and Flag::modify functions in Bugzilla 2.17.1 to 2.18.1 and 2.19.1 to 2.19.3 do not verify that the flag ID is appropriate for the given bug or attachment ID, which allows users to change flags on arbitrary bugs and obtain a bug summary via process_bug.cgi.

EPSS

Процентиль: 59%
0.00384
Низкий

Связанные уязвимости

ubuntu
около 20 лет назад

The Flag::validate and Flag::modify functions in Bugzilla 2.17.1 to 2.18.1 and 2.19.1 to 2.19.3 do not verify that the flag ID is appropriate for the given bug or attachment ID, which allows users to change flags on arbitrary bugs and obtain a bug summary via process_bug.cgi.

nvd
около 20 лет назад

The Flag::validate and Flag::modify functions in Bugzilla 2.17.1 to 2.18.1 and 2.19.1 to 2.19.3 do not verify that the flag ID is appropriate for the given bug or attachment ID, which allows users to change flags on arbitrary bugs and obtain a bug summary via process_bug.cgi.

debian
около 20 лет назад

The Flag::validate and Flag::modify functions in Bugzilla 2.17.1 to 2. ...

EPSS

Процентиль: 59%
0.00384
Низкий