{"id":"MGASA-2018-0173","summary":"Updated bugzilla packages fix security vulnerability","details":"A CSRF vulnerability in Bugzilla's report.cgi would allow a third-party\nsite to extract confidential information from a bug the victim had\naccess to (CVE-2018-5123).\n","modified":"2026-04-16T06:25:08.950065595Z","published":"2018-03-19T12:13:14Z","upstream":["CVE-2018-5123"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2018-0173.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=22735"},{"type":"WEB","url":"https://www.bugzilla.org/security/4.4.12/"},{"type":"WEB","url":"https://www.bugzilla.org/releases/5.0.4/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/P5C2KWZ264F2MRWTJ2AJWMBZX7MOKV4W/"}],"affected":[{"package":{"name":"bugzilla","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/bugzilla?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.0.4-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2018-0173.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}