MEDIUM
bugzilla: CSRF vuln via editkeywords.cgi and userprefs.cgi
Published Feb 9, 2009
5.8
MEDIUMCVSS 2.0
EPSS 0.60%
Description
Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.22 before 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delete keywords and user preferences via a link or IMG tag to (1) editkeywords.cgi or (2) userprefs.cgi.
Affected products
No data.
OR
- 2.10
- 2.12
- 2.14
- 2.14.1
- 2.14.2
- 2.14.3
- 2.14.4
- 2.14.5
- 2.16
- 2.16
- 2.16.1
- 2.16.2
- 2.16.3
- 2.16.4
- 2.16.5
- 2.16.6
- 2.16.7
- 2.16.8
- 2.16.9
- 2.16.10
- 2.16.11
- 2.16_rc2
- 2.17
- 2.17.1
- 2.17.2
- 2.17.3
- 2.17.4
- 2.17.5
- 2.17.6
- 2.17.7
- 2.18
- 2.18
- 2.18
- 2.18
- 2.18.1
- 2.18.2
- 2.18.3
- 2.18.4
- 2.18.5
- 2.18.6
- 2.18.7
- 2.18.8
- 2.18.9
- 2.19
- 2.19.1
- 2.19.2
- 2.19.3
- 2.20
- 2.20
- 2.20
- 2.20.1
- 2.20.2
- 2.20.3
- 2.20.4
- 2.20.5
- 2.20.6
- 2.21
- 2.21.1
- 2.21.2
- 2.22
- 2.22
- 2.22.1
- 2.22.2
- 2.22.3
- 2.22.4
- 2.22.5
- 2.22.6
- 3.0.0
- 3.0.1
- 3.0.2
- 3.0.3
- 3.0.4
- 3.0.5
- 3.0.6
- 3.2
- 3.3.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (11)
- http://secunia.com/advisories/34361 third-party-advisoryx_refsource_SECUNIA
- http://www.bugzilla.org/security/2.22.6/ x_refsource_CONFIRM
- http://www.securityfocus.com/bid/33580 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2009-0483 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=466692 x_refsource_CONFIRM
- https://bugzilla.mozilla.org/show_bug.cgi?id=472362 x_refsource_CONFIRM
- https://bugzilla.redhat.com/show_bug.cgi?id=484807 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2009-0483
- https://www.cve.org/CVERecord?id=CVE-2009-0483
- https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00664.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00687.html vendor-advisoryx_refsource_FEDORA
| Link | Providers | Tags |
|---|---|---|
| http://secunia.com/advisories/34361 | third-party-advisoryx_refsource_SECUNIA | |
| http://www.bugzilla.org/security/2.22.6/ | x_refsource_CONFIRM | |
| http://www.securityfocus.com/bid/33580 | vdb-entryx_refsource_BID | |
| https://access.redhat.com/security/cve/CVE-2009-0483 | Vendor Advisory | |
| https://bugzilla.mozilla.org/show_bug.cgi?id=466692 | x_refsource_CONFIRM | |
| https://bugzilla.mozilla.org/show_bug.cgi?id=472362 | x_refsource_CONFIRM | |
| https://bugzilla.redhat.com/show_bug.cgi?id=484807 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2009-0483 | ||
| https://www.cve.org/CVERecord?id=CVE-2009-0483 | ||
| https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00664.html | vendor-advisoryx_refsource_FEDORA | |
| https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00687.html | vendor-advisoryx_refsource_FEDORA |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 9, 2009
Updated Aug 7, 2024
Reserved Feb 9, 2009
Link CVE-2009-0483
CISA Vulnrichment
Updated n/a