CVE-2014-1571: Fedoraproject Fedora

Medium severity, CVSS 4.0. EPSS: 1.4% chance of exploitation in the next 30 days.

Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 allows remote authenticated users to obtain sensitive private-comment information by leveraging a role as a flag recipient, related to Bug.pm, Flag.pm, and a mail template.

Affected products

  • Fedoraproject Fedora: version 19 only; version 20 only; version 21 only
  • Mozilla Bugzilla: version 2.0 only; version 2.2 only; version 2.4 only; version 2.6 only; version 2.8 only; version 2.9 only; …

Published 2014-10-13. Last modified 2026-06-17.