Information Disclosure in Bugzilla Web Service for Version 4.3.2
CVE-2012-5884
Currently unrated
What is CVE-2012-5884?
The Bugzilla web service, specifically the User.get method in Bugzilla 4.3.2, is susceptible to a vulnerability that enables remote attackers to access sensitive user data. By leveraging either XMLRPC or JSONRPC requests, an attacker can retrieve details about saved searches of arbitrary users, potentially leading to unauthorized information exposure. This presents a significant risk for user privacy and data confidentiality within the Bugzilla application.