Search CVE reports


Toggle filters

21 – 30 of 51 results


CVE-2021-29274

Medium priority
Not affected

Redmine 4.1.x before 4.1.2 allows XSS because an issue's subject is mishandled in the auto complete tip.

1 affected package

redmine

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redmine Not affected Not affected
Show less packages

CVE-2019-18890

Medium priority
Fixed

A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crafted object query.

1 affected package

redmine

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redmine Not affected
Show less packages

CVE-2019-17427

Medium priority
Fixed

In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.

1 affected package

redmine

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redmine Fixed
Show less packages

CVE-2017-18026

Medium priority

Some fixes available 1 of 6

Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary commands (through the Mercurial...

1 affected package

redmine

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redmine Not in release Not in release Not in release Not affected Not affected
Show less packages

CVE-2017-16804

Medium priority

Some fixes available 1 of 6

In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function in app/models/mailer.rb does not check whether an issue is visible, which allows remote authenticated users to obtain sensitive information by reading e-mail...

1 affected package

redmine

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redmine Not in release Not in release Not in release Not affected Not affected
Show less packages

CVE-2017-15577

Medium priority

Some fixes available 1 of 4

Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows remote attackers to obtain sensitive information.

1 affected package

redmine

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redmine Not in release Not in release Not in release Not affected Not affected
Show less packages

CVE-2017-15576

Low priority

Some fixes available 1 of 6

Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensitive information.

1 affected package

redmine

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redmine Not in release Not in release Not in release Not affected Not affected
Show less packages

CVE-2017-15575

Low priority

Some fixes available 1 of 6

In Redmine before 3.2.6 and 3.3.x before 3.3.3, Redmine.pm lacks a check for whether the Repository module is enabled in a project's settings, which might allow remote attackers to obtain sensitive differences information...

1 affected package

redmine

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redmine Not in release Not in release Not in release Not affected Not affected
Show less packages

CVE-2017-15574

Medium priority

Some fixes available 1 of 6

In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using an SVG document as an attachment.

1 affected package

redmine

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redmine Not in release Not in release Not in release Not affected Not affected
Show less packages

CVE-2017-15573

Medium priority

Some fixes available 1 of 6

In Redmine before 3.2.6 and 3.3.x before 3.3.3, XSS exists because markup is mishandled in wiki content.

1 affected package

redmine

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redmine Not in release Not in release Not in release Not affected Not affected
Show less packages