Back

LOW

bugzilla: Account Impersonation via email interface

Published May 7, 2008

Description

email_in.pl in Bugzilla 2.23.4, 3.0.x before 3.0.4, and 3.1.x before 3.1.4 allows remote authenticated users to more easily spoof the changer of a bug via a @reporter command in the body of an e-mail message, which overrides the e-mail address as normally obtained from the From e-mail header. NOTE: since From headers are easily spoofed, this only crosses privilege boundaries in environments that provide additional verification of e-mail addresses.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 7, 2008
Updated Aug 7, 2024
Reserved May 7, 2008
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date May 4, 2008