Skip to main content

Vendor archive

redmine CVEs

Beta · best-effort

51 CVEs tagged to vendor redmine1 Critical, 12 High, 38 Medium, 0 Low, 0 Unrated.

CVE-2023-47260

Published Nov 5, 2023

Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS via thumbnails.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-47259

Published Nov 5, 2023

Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in the Textile formatter.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-47258

Published Nov 5, 2023

Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in a Markdown formatter.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-44637

Published Dec 12, 2022

Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization in Redcloth3 Textile-formatted fields. Depending on the con…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-44031

Published Dec 12, 2022

Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization of the blockquote syntax in Textile-formatted fields.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-44030

Published Dec 6, 2022

Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the configuration, this may requi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-42326

Published Oct 12, 2021

Redmine before 4.1.5 and 4.2.x before 4.2.3 may disclose the names of users on activity views due to an insufficient access filter.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37156

Published Aug 5, 2021

Redmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling two-factor authentication for the user's account, but the intended behavior is for those sessions to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-31866

Published Apr 28, 2021

Redmine before 4.0.9 and 4.1.x before 4.1.3 allows an attacker to learn the values of internal authentication keys by observing timing differences in string comparison operations…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-31865

Published Apr 28, 2021

Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows users to circumvent the allowed filename extensions of uploaded attachments.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-31864

Published Apr 28, 2021

Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows attackers to bypass the add_issue_notes permission requirement by leveraging the incoming mail handler.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-31863

Published Apr 28, 2021

Insufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows Redmine users to read arbitrary local fi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-30164

Published Apr 6, 2021

Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_issue_notes permission requirement by leveraging the Issues API.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-30163

Published Apr 6, 2021

Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the names of private projects if issue-journal details exist that have changes to project_id values.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36308

Published Apr 6, 2021

Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performing a CSV export and reading time entries.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29274

Published Mar 29, 2021

Redmine 4.1.x before 4.1.2 allows XSS because an issue's subject is mishandled in the auto complete tip.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-18890

Published Nov 21, 2019

A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crafted object query.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-17427

Published Oct 10, 2019

In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18026

Published Jan 10, 2018

Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to exe…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-16804

Published Nov 13, 2017

In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function in app/models/mailer.rb does not check whether an issue is visible, which allows remote authenticated users…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 51 CVEsPage 1 of 3