CVE-2014-1517
Publication date 20 April 2014
Last updated 24 July 2024
Ubuntu priority
The login form in Bugzilla 2.x, 3.x, 4.x before 4.4.3, and 4.5.x before 4.5.3 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker’s account and then submit a vulnerability report, related to a “login CSRF” issue.
Status
Package | Ubuntu Release | Status |
---|---|---|
bugzilla | 14.04 LTS trusty | Not in release |