Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Critical Flaw in Bugzilla Could Expose Zero-Day Bugs

Mozilla’s web-based bug tracker Bugzilla is plagued by a critical vulnerability that allows an attacker to register accounts with apparently privileged email addresses and possibly gain access to sensitive bug information.

Mozilla’s web-based bug tracker Bugzilla is plagued by a critical vulnerability that allows an attacker to register accounts with apparently privileged email addresses and possibly gain access to sensitive bug information.

The vulnerability, identified by PerimeterX senior vulnerability researcher Netanel Rubin, affects Bugzilla deployments that use email-based permissions. Bugzilla users that rely on this model assign privileges to newly created accounts based on the email address that is used for registration. If the email address is on a domain associated with a trusted organization, the user is granted elevated privileges (i.e. they are given access to sensitive information).

For example, in the case of bugzilla.mozilla.org, anyone registering an account with a mozilla.com email address is granted access to confidential bugs.

Gaining privileged access to private bug reports poses a serious risk, as demonstrated by a recent incident involving bugzilla.mozilla.org. An attacker gained access to the details of 185 non-public vulnerabilities after stealing the credentials of a privileged Bugzilla user. While it seems that most of these security holes have not been exploited in the wild, at least one of them has been leveraged to steal files from users’ computers.

The problem discovered and reported by Rubin is that in unpatched versions of Bugzilla an attacker can create an account using an email address in any domain, even if they don’t actually own the said email account.

The vulnerability (CVE-2015-4499) is caused by the fact that a field in the database storing user registration data is set to “tinytext,” which represents a text string of maximum 255 bytes. If more than 255 bytes are inserted, the data is truncated, which allows a malicious actor to register an account using their own email address while tricking Bugzilla into thinking that it’s an address on a privileged domain.

When users register on Bugzilla, they have to click on a link received via email to confirm that they are the owners of the account. Since the entered email address is truncated in the database, the attacker can use an address like “aaaa[…]aaa @mozilla.com. attackerdomain.com” and the “.attackerdomain.com” part is trimmed when the validation is performed, resulting in Bugzilla treating the account as being registerd with a mozilla.com address. However, the email containing the confirmation link is still sent to the attacker’s email account. Rubin says the validation flaw is triggered if the address is longer than 127 characters.

The vulnerability, reported by Rubin on September 7, affects Bugzilla versions 2.0 through 4.2.14, 4.3.1 through 4.4.9, and 4.5.1 through 5.0. The issue has been patched in versions 4.2.15, 4.4.10, 5.0.1.

Advertisement. Scroll to continue reading.

Since a large number of software projects use Bugzilla for tracking bugs, many serious vulnerabilities could become exposed before they are patched. Organizations using Bugzilla have been informed of the existence of patches and some of them, including the maintainers of Red Hat and Gentoo, have confirmed applying them.

“If you are using email based permissions in your Bugzilla deployment and have not yet installed a patched version, take it down until patched. Make sure to go over the logs and user-list to identify users that were created using this vulnerability. This vulnerability is extremely easy to exploit and the details have been known for more than a week, you have been or will be attacked!” Rubin warned in a blog post.

This is not the first time Rubin has found a Bugzilla vulnerability exposing undisclosed bugs. Back in October 2014, when he worked for Check Point Technologies, the researcher discovered a flaw that allowed him to create accounts with names that ensured privileged access to all bug reports.

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Bill Dunnion has joined telecommunications giant Mitel as Chief Information Security Officer.

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

More People On The Move

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

Vulnerabilities

A researcher at IOActive discovered that home security systems from SimpliSafe are plagued by a vulnerability that allows tech savvy burglars to remotely disable...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Vulnerabilities

Patch Tuesday: Microsoft warns vulnerability (CVE-2023-23397) could lead to exploitation before an email is viewed in the Preview Pane.

IoT Security

A vulnerability affecting Dahua cameras and video recorders can be exploited by threat actors to modify a device’s system time.