Search.pm in Bugzilla 2.19.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 allows remote attackers to determine the group memberships of arbitrary users via vectors involving the Search interface, boolean charts, and group-based pronouns.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2010-08-13T19:00:00
Updated: 2024-08-07T02:46:48.659Z
Reserved: 2010-07-14T00:00:00
Link: CVE-2010-2756
Vulnrichment
No data.
NVD
Status : Modified
Published: 2010-08-16T15:14:12.290
Modified: 2024-11-21T01:17:19.050
Link: CVE-2010-2756
Redhat
No data.