Unknown vulnerability in the administrative controls in Bugzilla 2.17.1 through 2.17.7 allows users with "grant membership" privileges to grant memberships to groups that the user does not control.
https://exchange.xforce.ibmcloud.com/vulnerabilities/16672