Search.pm in Bugzilla 2.19.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 allows remote attackers to determine the group memberships of arbitrary users via vectors involving the Search interface, boolean charts, and group-based pronouns.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T02:46:48.659Z
Reserved: 2010-07-14T00:00:00
Link: CVE-2010-2756

No data.

Status : Deferred
Published: 2010-08-16T15:14:12.290
Modified: 2025-04-11T00:51:21.963
Link: CVE-2010-2756

No data.