|
|
| |
|
| |
bugzilla: multiple vulnerabilities
| Package(s): | bugzilla |
CVE #(s): | |
| Created: | November 26, 2012 |
Updated: | November 28, 2012 |
| Description: |
From the Fedora advisory:
Update to 4.0.9
- Confidential product and component names can be disclosed to unauthorized users if they are used
to control the visibility of a custom field.
- When calling the 'User.get' WebService method with a 'groups' argument, it is possible to check
if the given group names exist or not.
- Due to incorrectly filtered field values in tabular reports, it is possible to inject code which
can lead to XSS.
- When trying to mark an attachment in a bug you cannot see as obsolete, the description of the
attachment is disclosed in the error message.
- A vulnerability in swfstore.swf from YUI2 can lead to XSS.
|
| Alerts: |
|
( Log in to post comments)
|
|
|