Search CVE reports


Toggle filters

21 – 30 of 50 results


CVE-2019-18890

Medium priority
Fixed

A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crafted object query.

1 affected package

redmine

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
redmine Not affected Fixed
Show less packages

CVE-2019-17427

Medium priority
Fixed

In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.

1 affected package

redmine

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
redmine Fixed Fixed
Show less packages

CVE-2017-18026

Medium priority

Some fixes available 1 of 6

Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary commands (through the Mercurial...

1 affected package

redmine

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
redmine Not in release Not in release Not affected Not affected Vulnerable
Show less packages

CVE-2017-16804

Medium priority

Some fixes available 1 of 6

In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function in app/models/mailer.rb does not check whether an issue is visible, which allows remote authenticated users to obtain sensitive information by reading e-mail...

1 affected package

redmine

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
redmine Not in release Not in release Not affected Not affected Vulnerable
Show less packages

CVE-2017-15577

Medium priority

Some fixes available 1 of 4

Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows remote attackers to obtain sensitive information.

1 affected package

redmine

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
redmine Not in release Not in release Not affected Not affected Vulnerable
Show less packages

CVE-2017-15576

Low priority

Some fixes available 1 of 6

Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensitive information.

1 affected package

redmine

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
redmine Not in release Not in release Not affected Not affected Vulnerable
Show less packages

CVE-2017-15575

Low priority

Some fixes available 1 of 6

In Redmine before 3.2.6 and 3.3.x before 3.3.3, Redmine.pm lacks a check for whether the Repository module is enabled in a project's settings, which might allow remote attackers to obtain sensitive differences information...

1 affected package

redmine

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
redmine Not in release Not in release Not affected Not affected Vulnerable
Show less packages

CVE-2017-15574

Medium priority

Some fixes available 1 of 6

In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using an SVG document as an attachment.

1 affected package

redmine

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
redmine Not in release Not in release Not affected Not affected Vulnerable
Show less packages

CVE-2017-15573

Medium priority

Some fixes available 1 of 6

In Redmine before 3.2.6 and 3.3.x before 3.3.3, XSS exists because markup is mishandled in wiki content.

1 affected package

redmine

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
redmine Not in release Not in release Not affected Not affected Vulnerable
Show less packages

CVE-2017-15572

Medium priority

Some fixes available 1 of 4

In Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sensitive information (password reset tokens) by reading a Referer log, because account/lost_password does not use a redirect.

1 affected package

redmine

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
redmine Not in release Not in release Not affected Not affected Vulnerable
Show less packages