Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The WebService (XML-RPC) interface in Bugzilla 2.23.3 through 3.0.0 does not enforce permissions for the time-tracking fields of bugs, which allows remote attackers to obtain sensitive information via certain XML-RPC requests, as demonstrated by the (1) Deadline and (2) Estimated Time fields.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Bugzilla 多个远程漏洞
Vulnerability Description
Bugzilla 2.23.3 至3.0.0版本中的WebService (XML-RPC)界面没有执行对bugs字段的时间跟踪,这会允许远程攻击者可以借助某些XML-RPC请求, 例如(1) Deadline和(2) Estimated Time字段,获得敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A