Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Redmine
(Redmine)Repositories | https://github.com/redmine/redmine |
#Vulnerabilities | 50 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2019-11-21 | CVE-2019-18890 | A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crafted object query. | Debian_linux, Redmine | N/A | ||
2019-10-10 | CVE-2019-17427 | In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors. | Redmine | N/A | ||
2018-01-10 | CVE-2017-18026 | Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary commands (through the Mercurial adapter) via vectors involving a branch whose name begins with a --config= or --debugger= substring, a related issue to CVE-2017-17536. | Debian_linux, Redmine | 8.8 | ||
2017-10-18 | CVE-2017-15575 | In Redmine before 3.2.6 and 3.3.x before 3.3.3, Redmine.pm lacks a check for whether the Repository module is enabled in a project's settings, which might allow remote attackers to obtain sensitive differences information or possibly have unspecified other impact. | Debian_linux, Redmine | 7.3 | ||
2017-11-13 | CVE-2017-16804 | In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function in app/models/mailer.rb does not check whether an issue is visible, which allows remote authenticated users to obtain sensitive information by reading e-mail reminder messages. | Debian_linux, Redmine | 4.3 | ||
2017-10-18 | CVE-2017-15577 | Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows remote attackers to obtain sensitive information. | Debian_linux, Redmine | 7.5 | ||
2017-10-18 | CVE-2017-15576 | Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensitive information. | Debian_linux, Redmine | 7.5 | ||
2017-10-18 | CVE-2017-15574 | In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using an SVG document as an attachment. | Debian_linux, Redmine | 6.1 | ||
2017-10-18 | CVE-2017-15573 | In Redmine before 3.2.6 and 3.3.x before 3.3.3, XSS exists because markup is mishandled in wiki content. | Debian_linux, Redmine | 6.1 | ||
2017-10-18 | CVE-2017-15572 | In Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sensitive information (password reset tokens) by reading a Referer log, because account/lost_password does not use a redirect. | Debian_linux, Redmine | 7.5 |