A CSRF vulnerability in Bugzilla's report.cgi would allow a third-party site to extract confidential information from a bug the victim had access to (CVE-2018-5123).
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2018-0173.json"