CVE-2012-4198 Information
Feb 14, 2021
cve
Description
The User.get method in Bugzilla/WebService/User.pm in Bugzilla 3.7.x and 4.0.x before 4.0.9 4.1.x and 4.2.x before 4.2.4 and 4.3.x and 4.4.x before 4.4rc1 has a different outcome for a groups request depending on whether a group exists which allows remote authenticated users to discover private group names by observing whether a call throws an error.
Reference
http://www.bugzilla.org/security/3.6.11/ http://www.mandriva.com/security/advisories?name=MDVSA-2013:066 https://bugzilla.mozilla.org/show_bug.cgi?id=781850
Share on: