CVE

Id
68866  
CVE No.
CVE-2014-1571  
Status
Candidate  
Description
Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 allows remote authenticated users to obtain sensitive private-comment information by leveraging a role as a flag recipient, related to Bug.pm, Flag.pm, and a mail template.  
Phase
Assigned (20140116)  
Votes
None (candidate not yet proposed)  
Comments