Code Injection in Bugzilla - CVE-2011-2381
Published: August 9, 2011 / Updated: August 11, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to manipulate data.
CRLF injection vulnerability in Bugzilla 2.17.1 through 2.22.7, 3.0.x through 3.3.x, 3.4.x before 3.4.12, 3.5.x, 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.3 allows remote attackers to inject arbitrary e-mail headers via an attachment description in a flagmail notification.