MEDIUM
bugzilla: CSRF vulnerability in attachment editing
Published Apr 1, 2009
6.8
MEDIUMCVSS 2.0
EPSS 0.69%
Description
Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 3.2 before 3.2.3, 3.3 before 3.3.4, and earlier versions allows remote attackers to hijack the authentication of arbitrary users for requests that use attachment editing.
Affected products
No data.
OR
- 3.2
- 3.2
- 3.2
- 3.2.1
- 3.2.2
- 3.3
- 3.3.1
- 3.3.2
- 3.3.3
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (14)
- http://secunia.com/advisories/34545 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/34547 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/34624 third-party-advisoryx_refsource_SECUNIA
- http://www.bugzilla.org/security/3.2.2/ x_refsource_CONFIRMPatchVendor Advisory
- http://www.securityfocus.com/bid/34308 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2009/0887 vdb-entryx_refsource_VUPENPatchVendor Advisory
- https://access.redhat.com/security/cve/CVE-2009-1213 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=476603 x_refsource_CONFIRMVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=494398 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49524 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2009-1213
- https://www.cve.org/CVERecord?id=CVE-2009-1213
- https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00188.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00191.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 1, 2009
Updated Aug 7, 2024
Reserved Mar 31, 2009
Link CVE-2009-1213
CISA Vulnrichment
Updated n/a