Redmine

Redmine

51 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 28.95%
  • Published 21.11.2019 18:15:11
  • Last modified 21.11.2024 04:33:47

A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crafted object query.

  • EPSS 2.17%
  • Published 10.10.2019 02:05:46
  • Last modified 21.11.2024 04:32:18

In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.

  • EPSS 0.75%
  • Published 10.01.2018 09:29:00
  • Last modified 21.11.2024 03:19:11

Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary commands (through the Mercurial adapter) via vectors inv...

  • EPSS 0.35%
  • Published 13.11.2017 20:29:00
  • Last modified 20.04.2025 01:37:25

In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function in app/models/mailer.rb does not check whether an issue is visible, which allows remote authenticated users to obtain sensitive information by reading e-mail reminder messages.

  • EPSS 0.54%
  • Published 18.10.2017 02:29:00
  • Last modified 20.04.2025 01:37:25

Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensitive information.

  • EPSS 0.54%
  • Published 18.10.2017 02:29:00
  • Last modified 20.04.2025 01:37:25

Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows remote attackers to obtain sensitive information.

  • EPSS 0.72%
  • Published 18.10.2017 02:29:00
  • Last modified 20.04.2025 01:37:25

In Redmine before 3.2.6 and 3.3.x before 3.3.3, Redmine.pm lacks a check for whether the Repository module is enabled in a project's settings, which might allow remote attackers to obtain sensitive differences information or possibly have unspecified...

  • EPSS 0.38%
  • Published 18.10.2017 02:29:00
  • Last modified 20.04.2025 01:37:25

In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using an SVG document as an attachment.

  • EPSS 0.38%
  • Published 18.10.2017 02:29:00
  • Last modified 20.04.2025 01:37:25

In Redmine before 3.2.6 and 3.3.x before 3.3.3, XSS exists because markup is mishandled in wiki content.

  • EPSS 0.58%
  • Published 18.10.2017 02:29:00
  • Last modified 20.04.2025 01:37:25

In Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sensitive information (password reset tokens) by reading a Referer log, because account/lost_password does not use a redirect.