CVE-2014-1985Improper Input Validation in Redmine

Severity
7.4HIGHNVD
NVD5.8OSV5.8
EPSS
1.8%
top 17.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 11
Latest updateMay 17

Description

Open redirect vulnerability in the redirect_back_or_default function in app/controllers/application_controller.rb in Redmine before 2.4.5 and 2.5.x before 2.5.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the back url (back_url parameter).

CVSS vector

AV:N/AC:M/C:P/I:P/A:NExploitability: 8.6 | Impact: 4.9

Affected Packages3 packages

debiandebian/redmine< redmine 3.2.0-1 (bookworm)+1
Debianredmine/redmine< 2.5.1-1+3
NVDredmine/redmine2.4.4+13

Also affects: Debian Linux 7.0, 8.0

Patches

🔴Vulnerability Details

4
GHSA
GHSA-m9hg-vq2w-vj4r: Open redirect vulnerability in the redirect_back_or_default function in app/controllers/application_controller2022-05-17
GHSA
GHSA-jf8c-hh25-c3q7: Open redirect vulnerability in the valid_back_url function in app/controllers/application_controller2022-05-17
OSV
CVE-2015-8474: Open redirect vulnerability in the valid_back_url function in app/controllers/application_controller2016-04-12
OSV
CVE-2014-1985: Open redirect vulnerability in the redirect_back_or_default function in app/controllers/application_controller2014-04-11

📋Vendor Advisories

2
Debian
CVE-2015-8474: redmine - Open redirect vulnerability in the valid_back_url function in app/controllers/ap...2015
Debian
CVE-2014-1985: redmine - Open redirect vulnerability in the redirect_back_or_default function in app/cont...2014