The sudo feature in Bugzilla 2.22rc1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 does not properly send impersonation notifications, which makes it easier for remote authenticated users to impersonate other users without discovery.
2010-08-16T15:14:12.320
2025-04-11T00:51:21.963
Deferred
CVSSv2: 6.5 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mozilla | bugzilla | 2.4 | Yes |
Application | mozilla | bugzilla | 2.6 | Yes |
Application | mozilla | bugzilla | 2.8 | Yes |
Application | mozilla | bugzilla | 2.9 | Yes |
Application | mozilla | bugzilla | 2.22 | Yes |
Application | mozilla | bugzilla | 2.22 | Yes |
Application | mozilla | bugzilla | 2.22.1 | Yes |
Application | mozilla | bugzilla | 2.22.3 | Yes |
Application | mozilla | bugzilla | 2.22.4 | Yes |
Application | mozilla | bugzilla | 2.22.5 | Yes |
Application | mozilla | bugzilla | 2.22.6 | Yes |
Application | mozilla | bugzilla | 2.22.7 | Yes |
Application | mozilla | bugzilla | 2.23 | Yes |
Application | mozilla | bugzilla | 2.23.1 | Yes |
Application | mozilla | bugzilla | 2.23.2 | Yes |
Application | mozilla | bugzilla | 2.23.3 | Yes |
Application | mozilla | bugzilla | 2.23.4 | Yes |
Application | mozilla | bugzilla | 3.0 | Yes |
Application | mozilla | bugzilla | 3.0 | Yes |
Application | mozilla | bugzilla | 3.0.0 | Yes |
Application | mozilla | bugzilla | 3.0.1 | Yes |
Application | mozilla | bugzilla | 3.0.2 | Yes |
Application | mozilla | bugzilla | 3.0.3 | Yes |
Application | mozilla | bugzilla | 3.0.4 | Yes |
Application | mozilla | bugzilla | 3.0.5 | Yes |
Application | mozilla | bugzilla | 3.0.6 | Yes |
Application | mozilla | bugzilla | 3.0.7 | Yes |
Application | mozilla | bugzilla | 3.0.8 | Yes |
Application | mozilla | bugzilla | 3.0.9 | Yes |
Application | mozilla | bugzilla | 3.0.10 | Yes |
Application | mozilla | bugzilla | 3.0.11 | Yes |
Application | mozilla | bugzilla | 3.1.0 | Yes |
Application | mozilla | bugzilla | 3.1.1 | Yes |
Application | mozilla | bugzilla | 3.1.2 | Yes |
Application | mozilla | bugzilla | 3.1.3 | Yes |
Application | mozilla | bugzilla | 3.2 | Yes |
Application | mozilla | bugzilla | 3.2.2 | Yes |
Application | mozilla | bugzilla | 3.2.3 | Yes |
Application | mozilla | bugzilla | 3.2.4 | Yes |
Application | mozilla | bugzilla | 3.2.5 | Yes |
Application | mozilla | bugzilla | 3.2.6 | Yes |
Application | mozilla | bugzilla | 3.2.7 | Yes |
Application | mozilla | bugzilla | 3.3.1 | Yes |
Application | mozilla | bugzilla | 3.3.2 | Yes |
Application | mozilla | bugzilla | 3.3.3 | Yes |
Application | mozilla | bugzilla | 3.3.4 | Yes |
Application | mozilla | bugzilla | 3.4.1 | Yes |
Application | mozilla | bugzilla | 3.4.2 | Yes |
Application | mozilla | bugzilla | 3.4.3 | Yes |
Application | mozilla | bugzilla | 3.4.4 | Yes |
Application | mozilla | bugzilla | 3.4.5 | Yes |
Application | mozilla | bugzilla | 3.4.6 | Yes |
Application | mozilla | bugzilla | 3.4.7 | Yes |
Application | mozilla | bugzilla | 3.5.1 | Yes |
Application | mozilla | bugzilla | 3.5.2 | Yes |
Application | mozilla | bugzilla | 3.5.3 | Yes |
Application | mozilla | bugzilla | 3.6 | Yes |
Application | mozilla | bugzilla | 3.6.1 | Yes |
Application | mozilla | bugzilla | 3.7 | Yes |
Application | mozilla | bugzilla | 3.7.1 | Yes |
Application | mozilla | bugzilla | 3.7.2 | Yes |