CVE-2014-1985 — Improper Input Validation in Redmine
Severity
7.4HIGHNVD
NVD5.8OSV5.8
EPSS
1.8%
top 17.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 11
Latest updateMay 17
Description
Open redirect vulnerability in the redirect_back_or_default function in app/controllers/application_controller.rb in Redmine before 2.4.5 and 2.5.x before 2.5.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the back url (back_url parameter).
CVSS vector
AV:N/AC:M/C:P/I:P/A:NExploitability: 8.6 | Impact: 4.9
Affected Packages3 packages
Also affects: Debian Linux 7.0, 8.0
Patches
🔴Vulnerability Details
4GHSA▶
GHSA-m9hg-vq2w-vj4r: Open redirect vulnerability in the redirect_back_or_default function in app/controllers/application_controller↗2022-05-17
GHSA▶
GHSA-jf8c-hh25-c3q7: Open redirect vulnerability in the valid_back_url function in app/controllers/application_controller↗2022-05-17
OSV▶
CVE-2015-8474: Open redirect vulnerability in the valid_back_url function in app/controllers/application_controller↗2016-04-12
OSV▶
CVE-2014-1985: Open redirect vulnerability in the redirect_back_or_default function in app/controllers/application_controller↗2014-04-11