CVE-2018-5123

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
29/04/2019
Last modified:
08/05/2019

Description

A third party website can access information available to a user with access to a restricted bug entry using the image generation in report.cgi in all Bugzilla versions prior to 4.4.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mozilla:bugzilla:*:*:*:*:*:*:*:* 4.4 (excluding)


References to Advisories, Solutions, and Tools