Information Disclosure in Bugzilla Web Service for Version 4.3.2
CVE-2012-5884

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
16 November 2012

What is CVE-2012-5884?

The Bugzilla web service, specifically the User.get method in Bugzilla 4.3.2, is susceptible to a vulnerability that enables remote attackers to access sensitive user data. By leveraging either XMLRPC or JSONRPC requests, an attacker can retrieve details about saved searches of arbitrary users, potentially leading to unauthorized information exposure. This presents a significant risk for user privacy and data confidentiality within the Bugzilla application.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.