Bugzilla 2.14之前的版本不能正确限制对机密漏洞的访问。Bugzilla用户借助(1)process_bug.cgi,(2)show_activity.cgi,(3)showvotes.cgi,(4)showdependencytree.cgi, (5)showdependencygraph.cgi,(6)showattachment.cgi,或者(7)describecomponents.cgi中修改的漏洞id参数绕过浏览许可。
Bugzilla 2.14之前的版本不能正确限制对机密漏洞的访问。Bugzilla用户借助(1)process_bug.cgi,(2)show_activity.cgi,(3)showvotes.cgi,(4)showdependencytree.cgi, (5)showdependencygraph.cgi,(6)showattachment.cgi,或者(7)describecomponents.cgi中修改的漏洞id参数绕过浏览许可。