LWN.net Logo

bugzilla: cross-site request forgery

Package(s):bugzilla CVE #(s):CVE-2009-1213
Created:April 7, 2009 Updated:June 4, 2010
Description: From the CVE entry: Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 3.2 before 3.2.3, 3.3 before 3.3.4, and earlier versions allows remote attackers to hijack the authentication of arbitrary users for requests that use attachment editing.
Alerts:
Gentoo 201006-19:02 2010-06-04
Fedora FEDORA-2009-3405 2009-04-07
Fedora FEDORA-2009-3410 2009-04-07

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds