The response function in the JSONP endpoint in WebService/Server/JSONRPC.pm in jsonrpc.cgi in Bugzilla 3.x and 4.x before 4.0.14, 4.1.x and 4.2.x before 4.2.10, 4.3.x and 4.4.x before 4.4.5, and 4.5.x before 4.5.5 accepts certain long callback values and does not restrict the initial bytes of a JSONP response, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and obtain sensitive information, via a crafted OBJECT element with SWF content consistent with the _bz_callback character set
Published Aug 14, 2014
4.3
MEDIUMCVSS 2.0
EPSS 0.54%
Description
The response function in the JSONP endpoint in WebService/Server/JSONRPC.pm in jsonrpc.cgi in Bugzilla 3.x and 4.x before 4.0.14, 4.1.x and 4.2.x before 4.2.10, 4.3.x and 4.4.x before 4.4.5, and 4.5.x before 4.5.5 accepts certain long callback values and does not restrict the initial bytes of a JSONP response, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and obtain sensitive information, via a crafted OBJECT element with SWF content consistent with the _bz_callback character set.
Affected products
No data.
- 3.0
- 3.0
- 3.0.0
- 3.0.1
- 3.0.2
- 3.0.3
- 3.0.4
- 3.0.5
- 3.0.6
- 3.0.7
- 3.0.8
- 3.0.9
- 3.0.10
- 3.0.11
- 3.1.0
- 3.1.1
- 3.1.2
- 3.1.3
- 3.1.4
- 3.2
- 3.2
- 3.2
- 3.2.1
- 3.2.2
- 3.2.3
- 3.2.4
- 3.2.5
- 3.2.6
- 3.2.7
- 3.2.8
- 3.2.9
- 3.2.10
- 3.3
- 3.3.1
- 3.3.2
- 3.3.3
- 3.3.4
- 3.4
- 3.4
- 3.4.1
- 3.4.2
- 3.4.3
- 3.4.4
- 3.4.5
- 3.4.6
- 3.4.7
- 3.4.8
- 3.4.9
- 3.4.10
- 3.4.11
- 3.4.12
- 3.4.13
- 3.5
- 3.5.1
- 3.5.2
- 3.5.3
- 3.6
- 3.6
- 3.6.0
- 3.6.1
- 3.6.2
- 3.6.3
- 3.6.4
- 3.6.5
- 3.6.6
- 3.6.7
- 3.6.8
- 3.6.9
- 3.6.10
- 3.6.11
- 3.6.12
- 3.6.13
- 3.7
- 3.7.1
- 3.7.2
- 3.7.3
- 4.0
- 4.0
- 4.0
- 4.0.1
- 4.0.2
- 4.0.3
- 4.0.4
- 4.0.5
- 4.0.6
- 4.0.7
- 4.0.8
- 4.0.9
- 4.0.10
- 4.0.11
- 4.0.12
- 4.0.13
- 4.1
- 4.1.1
- 4.1.2
- 4.1.3
- 4.2
- 4.2
- 4.2
- 4.2.1
- 4.2.2
- 4.2.3
- 4.2.4
- 4.2.5
- 4.2.6
- 4.2.7
- 4.2.8
- 4.2.9
- 4.3
- 4.3.1
- 4.3.2
- 4.3.3
- 4.4
- 4.4
- 4.4
- 4.4.1
- 4.4.2
- 4.4.3
- 4.4.4
- 4.5
- 4.5.1
- 4.5.2
- 4.5.3
- 4.5.4
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (8)
- http://advisories.mageia.org/MGASA-2014-0349.html x_refsource_CONFIRM
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136217.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136369.html vendor-advisoryx_refsource_FEDORA
- http://www.mandriva.com/security/advisories?name=MDVSA-2014:169 vendor-advisoryx_refsource_MANDRIVA
- http://www.securityfocus.com/archive/1/532895 mailing-listx_refsource_BUGTRAQ
- http://www.securitytracker.com/id/1030648 vdb-entryx_refsource_SECTRACK
- https://bugzilla.mozilla.org/show_bug.cgi?id=1036213 x_refsource_CONFIRMVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2014-1622 Advisory
| Link | Providers | Tags |
|---|---|---|
| http://advisories.mageia.org/MGASA-2014-0349.html | x_refsource_CONFIRM | |
| http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136217.html | vendor-advisoryx_refsource_FEDORA | |
| http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136369.html | vendor-advisoryx_refsource_FEDORA | |
| http://www.mandriva.com/security/advisories?name=MDVSA-2014:169 | vendor-advisoryx_refsource_MANDRIVA | |
| http://www.securityfocus.com/archive/1/532895 | mailing-listx_refsource_BUGTRAQ | |
| http://www.securitytracker.com/id/1030648 | vdb-entryx_refsource_SECTRACK | |
| https://bugzilla.mozilla.org/show_bug.cgi?id=1036213 | x_refsource_CONFIRMVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2014-1622 | Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data