CVE-2014-1573: Fedoraproject Fedora

Medium severity, CVSS 4.3. EPSS: 2.3% chance of exploitation in the next 30 days.

Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not ensure that a scalar context is used for certain CGI parameters, which allows remote attackers to conduct cross-site scripting (XSS) attacks by sending three values for a single parameter name.

Affected products

  • Fedoraproject Fedora: version 19 only; version 20 only; version 21 only
  • Mozilla Bugzilla: version 2.0 only; version 2.2 only; version 2.4 only; version 2.6 only; version 2.8 only; version 2.9 only; …

Published 2014-10-13. Last modified 2026-06-17.