Loading...
Loading...
The WebService (XML-RPC) interface in Bugzilla 2.23.3 through 3.0.0 does not enforce permissions for the time-tracking fields of bugs, which allows remote attackers to obtain sensitive information via certain XML-RPC requests, as demonstrated by the (1) Deadline and (2) Estimated Time fields.
August 27, 2007
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2007-4539
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.