Code Injection in Bugzilla - CVE-2011-2381
Published: August 9, 2011 / Updated: August 11, 2020
Bugzilla
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to manipulate data.
CRLF injection vulnerability in Bugzilla 2.17.1 through 2.22.7, 3.0.x through 3.3.x, 3.4.x before 3.4.12, 3.5.x, 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.3 allows remote attackers to inject arbitrary e-mail headers via an attachment description in a flagmail notification.