Security Advisory
CVE-2001-1406
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
process_bug.cgi in Bugzilla before 2.14 does not set the "groupset" bit when a bug is moved between product groups, which will cause the bug to have the old group's restrictions, which might not be as stringent.