This advisory covers three security bugs that have recently been discovered and fixed in the Bugzilla code: In the stable 2.16 releases, it is possible to make a specific change to a bug without permissions; and in the 2.18 release candidate, there are information leaks with private attachments and comments.
8f9c02f007a21f436c69cf3d72153a7a8d2ed21ef3cb018145a3e685a21f230a