Information Exposure in Bugzilla by Mozilla
CVE-2018-5123
8.8HIGH
What is CVE-2018-5123?
An issue in Bugzilla allows third-party websites to access sensitive information intended for restricted users. This occurs through a flaw in the image generation feature of report.cgi, affecting all versions before 4.4. As a result, attackers could exploit this vulnerability to gain unauthorized access to bug entries and other data, potentially leading to privacy breaches.
Affected Version(s)
Bugzilla All versions prior to Bugzilla 4.4