CVE-2012-0440
Summary
| CVE | CVE-2012-0440 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-02-02 18:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Cross-site request forgery (CSRF) vulnerability in jsonrpc.cgi in Bugzilla 3.5.x and 3.6.x before 3.6.8, 3.7.x and 4.0.x before 4.0.4, and 4.1.x and 4.2.x before 4.2rc2 allows remote attackers to hijack the authentication of arbitrary users for requests that use the JSON-RPC API. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:H/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Bugzilla | 3.5 | All | All | All |
| Application | Mozilla | Bugzilla | 3.5.1 | All | All | All |
| Application | Mozilla | Bugzilla | 3.5.2 | All | All | All |
| Application | Mozilla | Bugzilla | 3.5.3 | All | All | All |
| Application | Mozilla | Bugzilla | 3.6 | All | All | All |
| Application | Mozilla | Bugzilla | 3.6 | rc1 | All | All |
| Application | Mozilla | Bugzilla | 3.6.0 | All | All | All |
| Application | Mozilla | Bugzilla | 3.6.1 | All | All | All |
| Application | Mozilla | Bugzilla | 3.6.2 | All | All | All |
| Application | Mozilla | Bugzilla | 3.6.3 | All | All | All |
| Application | Mozilla | Bugzilla | 3.6.4 | All | All | All |
| Application | Mozilla | Bugzilla | 3.6.5 | All | All | All |
| Application | Mozilla | Bugzilla | 3.6.6 | All | All | All |
| Application | Mozilla | Bugzilla | 3.6.7 | All | All | All |
| Application | Mozilla | Bugzilla | 3.7 | All | All | All |
| Application | Mozilla | Bugzilla | 3.7.1 | All | All | All |
| Application | Mozilla | Bugzilla | 3.7.2 | All | All | All |
| Application | Mozilla | Bugzilla | 3.7.3 | All | All | All |
| Application | Mozilla | Bugzilla | 4.0 | All | All | All |
| Application | Mozilla | Bugzilla | 4.0 | rc1 | All | All |
| Application | Mozilla | Bugzilla | 4.0 | rc2 | All | All |
| Application | Mozilla | Bugzilla | 4.0.1 | All | All | All |
| Application | Mozilla | Bugzilla | 4.0.2 | All | All | All |
| Application | Mozilla | Bugzilla | 4.0.3 | All | All | All |
| Application | Mozilla | Bugzilla | 4.1 | All | All | All |
| Application | Mozilla | Bugzilla | 4.1.1 | All | All | All |
| Application | Mozilla | Bugzilla | 4.1.2 | All | All | All |
| Application | Mozilla | Bugzilla | 4.1.3 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2 | rc1 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 4.2.rc1, 4.0.3, 3.6.7, and 3.4.13 Security Advisory :: Bugzilla :: bugzilla.org | af854a3a-2127-422b-91ae-364da2661108 | www.bugzilla.org | Vendor Advisory |
| 718319 – (CVE-2012-0440) [SECURITY] JSON-RPC permits to bypass token checks and can lead to CSRF (no victim's action required) | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | Exploit, Patch |
| Security Advisory SA47814 - Bugzilla Spoofing and Cross-Site Request Forgery Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Bugzilla Bugs Permit Remote Cross-Site Request Forgery and Remote Authenticated Account Impersonation Attacks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.