Closed Bug 966183 Opened 11 years ago Closed 11 years ago

[Bug Bounty] [Vulnerability Report] Login CSRF On Bugzilla.Mozilla.org

Categories

(bugzilla.mozilla.org :: API, defect)

Development
x86_64
Windows 8
defect
Not set
normal

Tracking

()

RESOLVED DUPLICATE of bug 713926

People

(Reporter: pbssubhash, Unassigned)

Details

(Keywords: reporter-external, Whiteboard: [site:bugzilla.mozilla.org][reporter-external])

User Agent: Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.102 Safari/537.36 Steps to reproduce: Actually When we Login into bugzilla account there should be some csrf token and also header verification , But there is absolutely no protection for the signin form against csrf attack ! You may think whats the issue with login csrf ! There are even some people who are hearing this kindoff csrf attack for the first time, But infact now-a-days these type of attacks are carried out ; For example i give the victim a html form using which my account will be logged into. He wants to report some bug then when he goes to bugzilla.mozilla.org then he files that bug using my account ; i can get back to my account after some time and then i can publicize the bug and can cause harm to your infrastructure without giving the time for you to patch.. For eg:if it is a dos of firefox bug then i can use it to crash mozilla users and make them shift to some other browsers ! these can be a little bit devasting ! Please have a look into :- http://www.ethicalhack3r.co.uk/login-cross-site-request-forgery-csrf/ Actual results: When i was trying to login there was no token being generated and moreover there was no X-CSRF Header Protection ! Expected results: I expected that there must be a X-CSRF header and token verification that wouldn't allow this login csrf to happen !
Please add sec-bounty flag ! Regards
Flags: sec-bounty?
Group: core-security → bugzilla-security
Component: Untriaged → API
Product: Firefox → bugzilla.mozilla.org
Version: unspecified → Development/Staging
Already reported several times.
Status: UNCONFIRMED → RESOLVED
Closed: 11 years ago
Resolution: --- → DUPLICATE
Flags: sec-bounty? → sec-bounty-
Whiteboard: [site:bugzilla.mozilla.org][reporter-external]
Group: bugzilla-security
You need to log in before you can comment on or make changes to this bug.