CVE
- Id
- 4204
- CVE No.
- CVE-2001-1401
- Status
- Candidate
- Description
- Bugzilla before 2.14 does not properly restrict access to confidential bugs, which could allow Bugzilla users to bypass viewing permissions via modified bug id parameters in (1) process_bug.cgi, (2) show_activity.cgi, (3) showvotes.cgi, (4) showdependencytree.cgi, (5) showdependencygraph.cgi, (6) showattachment.cgi, or (7) describecomponents.cgi.
- Phase
- Proposed (20020830)
- Votes
- ACCEPT(6) Armstrong, Baker, Cole, Cox, Green, Wall | MODIFY(1) Frech | NOOP(1) Foat
- Comments
- Frech> XF:bugzilla-describe-components(7058) | XF:bugzilla-show-dependency-graph(7060) | XF:bugzilla-show-dependency-tree(7061) | XF:bugzilla-show-votes(7065) | XF:bugzilla-show-activity(7066) | XF:bugzilla-process-bug(7067) | XF:bugzilla-show-attachment(7070)