{"api_version":"1","generated_at":"2026-07-23T04:20:03+00:00","cve":"CVE-2011-2979","urls":{"html":"https://cve.report/CVE-2011-2979","api":"https://cve.report/api/cve/CVE-2011-2979.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2011-2979","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2011-2979"},"summary":{"title":"CVE-2011-2979","description":"Bugzilla 4.1.x before 4.1.3 generates different responses for certain assignee queries depending on whether the group name is valid, which allows remote attackers to determine the existence of private group names via a custom search.  NOTE: this vulnerability exists because of a CVE-2010-2756 regression.","state":"PUBLISHED","assigner":"mitre","published_at":"2011-08-09 19:55:01","updated_at":"2026-04-29 01:13:23"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.bugzilla.org/security/3.4.11/","name":"http://www.bugzilla.org/security/3.4.11/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"4.1.2, 4.0.1, 3.6.5, and 3.4.11 Security Advisory :: Bugzilla :: bugzilla.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=674497","name":"https://bugzilla.mozilla.org/show_bug.cgi?id=674497","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch"],"title":"674497 – (CVE-2011-2979) [SECURITY] Custom searches let you determine if a group exists or not","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/69166","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/69166","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/74298","name":"http://www.osvdb.org/74298","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.osvdb.org/74299","name":"http://www.osvdb.org/74299","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/49042","name":"http://www.securityfocus.com/bid/49042","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Bugzilla Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/45501","name":"http://secunia.com/advisories/45501","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Bugzilla Multiple Vulnerabilities - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2011/dsa-2322","name":"http://www.debian.org/security/2011/dsa-2322","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Debian -- Security Information -- DSA-2322-1 bugzilla","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2011-2979","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-2979","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2011","cve_id":"2979","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"bugzilla","cpe6":"4.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"2979","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"bugzilla","cpe6":"4.1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"2979","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"bugzilla","cpe6":"4.1.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T23:22:26.084Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"74298","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/74298"},{"name":"bugzilla-queries-info-disclosure(69166)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/69166"},{"name":"45501","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/45501"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.bugzilla.org/security/3.4.11/"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=674497"},{"name":"74299","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/74299"},{"name":"DSA-2322","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2011/dsa-2322"},{"name":"49042","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/49042"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2011-08-04T00:00:00.000Z","descriptions":[{"lang":"en","value":"Bugzilla 4.1.x before 4.1.3 generates different responses for certain assignee queries depending on whether the group name is valid, which allows remote attackers to determine the existence of private group names via a custom search.  NOTE: this vulnerability exists because of a CVE-2010-2756 regression."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"74298","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/74298"},{"name":"bugzilla-queries-info-disclosure(69166)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/69166"},{"name":"45501","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/45501"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.bugzilla.org/security/3.4.11/"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=674497"},{"name":"74299","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/74299"},{"name":"DSA-2322","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2011/dsa-2322"},{"name":"49042","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/49042"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2011-2979","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Bugzilla 4.1.x before 4.1.3 generates different responses for certain assignee queries depending on whether the group name is valid, which allows remote attackers to determine the existence of private group names via a custom search.  NOTE: this vulnerability exists because of a CVE-2010-2756 regression."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"74298","refsource":"OSVDB","url":"http://www.osvdb.org/74298"},{"name":"bugzilla-queries-info-disclosure(69166)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/69166"},{"name":"45501","refsource":"SECUNIA","url":"http://secunia.com/advisories/45501"},{"name":"http://www.bugzilla.org/security/3.4.11/","refsource":"CONFIRM","url":"http://www.bugzilla.org/security/3.4.11/"},{"name":"https://bugzilla.mozilla.org/show_bug.cgi?id=674497","refsource":"CONFIRM","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=674497"},{"name":"74299","refsource":"OSVDB","url":"http://www.osvdb.org/74299"},{"name":"DSA-2322","refsource":"DEBIAN","url":"http://www.debian.org/security/2011/dsa-2322"},{"name":"49042","refsource":"BID","url":"http://www.securityfocus.com/bid/49042"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2011-2979","datePublished":"2011-08-09T19:00:00.000Z","dateReserved":"2011-08-01T00:00:00.000Z","dateUpdated":"2024-08-06T23:22:26.084Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2011-08-09 19:55:01","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:bugzilla:4.1:*:*:*:*:*:*:*","matchCriteriaId":"85CDC579-6967-4E5C-B716-B2BC04F6DBF2"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:bugzilla:4.1.1:*:*:*:*:*:*:*","matchCriteriaId":"27783033-F558-427C-89A7-C3638C57F2A0"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:bugzilla:4.1.2:*:*:*:*:*:*:*","matchCriteriaId":"E91557C7-8C53-49C4-8BC5-7F86D4AA09B8"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2011","CveId":"2979","Ordinal":"1","Title":"CVE-2011-2979","CVE":"CVE-2011-2979","Year":"2011"},"notes":[{"CveYear":"2011","CveId":"2979","Ordinal":"1","NoteData":"Bugzilla 4.1.x before 4.1.3 generates different responses for certain assignee queries depending on whether the group name is valid, which allows remote attackers to determine the existence of private group names via a custom search.  NOTE: this vulnerability exists because of a CVE-2010-2756 regression.","Type":"Description","Title":"CVE-2011-2979"},{"CveYear":"2011","CveId":"2979","Ordinal":"2","NoteData":"2011-08-09","Type":"Other","Title":"Published"},{"CveYear":"2011","CveId":"2979","Ordinal":"3","NoteData":"2017-08-28","Type":"Other","Title":"Modified"}]}}}