Vulnerabilities
Vulnerable Software
Redmine:  >> Redmine  >> 0.2.1  Security Vulnerabilities
Redmine before 3.4.13 and 4.x before 4.0.6 mishandles markup data during Textile formatting.
CVSS Score
5.3
EPSS Score
0.004
Published
2021-04-06
Redmine before 4.0.7 and 4.1.x before 4.1.1 has XSS via the back_url field.
CVSS Score
6.1
EPSS Score
0.003
Published
2021-04-06
Redmine before 4.0.7 and 4.1.x before 4.1.1 has stored XSS via textile inline links.
CVSS Score
6.1
EPSS Score
0.004
Published
2021-04-06
Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performing a CSV export and reading time entries.
CVSS Score
5.3
EPSS Score
0.004
Published
2021-04-06
Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the names of private projects if issue-journal details exist that have changes to project_id values.
CVSS Score
7.5
EPSS Score
0.005
Published
2021-04-06
Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_issue_notes permission requirement by leveraging the Issues API.
CVSS Score
9.8
EPSS Score
0.002
Published
2021-04-06
A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crafted object query.
CVSS Score
6.5
EPSS Score
0.289
Published
2019-11-21
In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.
CVSS Score
6.1
EPSS Score
0.022
Published
2019-10-10
Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary commands (through the Mercurial adapter) via vectors involving a branch whose name begins with a --config= or --debugger= substring, a related issue to CVE-2017-17536.
CVSS Score
8.8
EPSS Score
0.008
Published
2018-01-10
In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function in app/models/mailer.rb does not check whether an issue is visible, which allows remote authenticated users to obtain sensitive information by reading e-mail reminder messages.
CVSS Score
4.3
EPSS Score
0.003
Published
2017-11-13


Contact Us

Shodan ® - All rights reserved