Bugzilla 3.2.1, 3.0.7, and 3.3.2, when running under mod_perl, generated insufficiently random numbers, resulting in all random tokens being the same, all CSRF protection being defeated, and the new attachment_base functionality being compromised.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/74582/bugzilla-xsrf.txt
Source: https://packetstormsecurity.com/files/74582/Bugzilla-XSRF-Randomization-Vulnerability.html