Bugzilla Crafted Parameter Information Disclosure Vulnerability
14 Mar. 2012
Summary
This allows remote attackers to determine the existence of private group names via a crafted parameter during (1) bug creation or (2) bug editing.
Credit:
The information has been provided by Frederic Buclin, Byron Jones, Max Kanat-Alexander, Reed Loden, Neal Poole, Neil Rashbrook, David Lawrence.
The original article can be found at: http://www.securityfocus.com/bid/49042/info
Vulnerable Systems:
* Bugzilla 2.23.3 to 3.4.11,
* Bugzilla 3.5.1 to 3.6.5,
* Bugzilla 3.7.1 to 4.0.1,
* Bugzilla4.1.1 to 4.1.2
Normally, a group name is confidential and is only visible to members of the group, and to non-members if the group is used in bugs. By crafting the URL when creating or editing a bug, it was possible to guess if a group existed or not, even for groups which weren't used in bugs and so which were supposed to remain confidential
Vendor Status:
Bugzilla has issued an update to correct this vulnerability