Back

CVE-2004-0703

Unknown vulnerability in the administrative controls in Bugzilla 2.17.1 through 2.17.7 allows users with "grant membership" privileges to grant memberships to groups that the user does not control.

Published: Jul 27, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (24)

Vendor Product Version
mozilla bugzilla 2.4
mozilla bugzilla 2.6
mozilla bugzilla 2.8
mozilla bugzilla 2.10
mozilla bugzilla 2.12
mozilla bugzilla 2.14
mozilla bugzilla 2.14.1
mozilla bugzilla 2.14.2
mozilla bugzilla 2.14.3
mozilla bugzilla 2.14.4
mozilla bugzilla 2.14.5
mozilla bugzilla 2.16
mozilla bugzilla 2.16.1
mozilla bugzilla 2.16.2
mozilla bugzilla 2.16.3
mozilla bugzilla 2.16.4
mozilla bugzilla 2.16.5
mozilla bugzilla 2.17
mozilla bugzilla 2.17.1
mozilla bugzilla 2.17.3

…and 4 more

GitHub Security Advisory GHSA-w523-7fpr-882h

Unknown vulnerability in the administrative controls in Bugzilla 2.17.1 through 2.17.7 allows...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.12%

Top 37% most likely to be exploited

Threat Score 30.3 / 100

Data Sources

NVD EPSS GitHub