Bugzilla 2.17.x, 2.18 before 2.18.2, 2.19.x, and 2.20 before 2.20rc1 inserts a bug into the database before it is marked private, which introduces a race condition and allows attackers to access information about the bug via buglist.cgi before MySQL replication is complete.
Exploitability
AV:NAC:HAu:NImpact
C:PI:NA:N2.6/AV:N/AC:H/Au:N/C:P/I:N/A:N