LWN.net Logo

bugzilla: cross-site request forgery

Package(s):bugzilla CVE #(s):CVE-2012-0453
Created:March 7, 2012 Updated:March 7, 2012
Description: Bugzilla does not properly validate form attributes passed to xmlrpc.cgi, enabling cross-site request forgery attacks.
Alerts:
Fedora FEDORA-2012-2398 2012-03-06

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds