CVE-2009-3989
Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for…
Does this matter?
Lower severity and a low EPSS score (1.53%). Track it; it rarely justifies an emergency change on its own.
Description
Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 1.53% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- mozilla/bugzilla
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/38443Vendor Advisory
- http://www.securityfocus.com/archive/1/509282/100/0/threaded
- http://www.securityfocus.com/bid/38025
- http://www.vupen.com/english/advisories/2010/0261Patch, Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=314871Patch
- https://bugzilla.mozilla.org/show_bug.cgi?id=434801Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56003
- http://secunia.com/advisories/38443Vendor Advisory
- http://www.securityfocus.com/archive/1/509282/100/0/threaded
- http://www.securityfocus.com/bid/38025
- http://www.vupen.com/english/advisories/2010/0261Patch, Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=314871Patch
- https://bugzilla.mozilla.org/show_bug.cgi?id=434801Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56003
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.