CVE-2015-8346Redmine vulnerability

CWE-1994 documents4 sources
Severity
5.3MEDIUMNVD
EPSS
0.5%
top 35.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 12
Latest updateMay 17

Description

app/views/timelog/_form.html.erb in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote attackers to obtain sensitive information about subjects of issues by viewing the time logging form.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

debiandebian/redmine< redmine 3.2.0-1 (bookworm)
Debianredmine/redmine< 3.2.0-1+1
NVDredmine/redmine2.6.7+8

Also affects: Debian Linux 8.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-62w5-cx7r-8pgp: app/views/timelog/_form2022-05-17
OSV
CVE-2015-8346: app/views/timelog/_form2016-04-12

📋Vendor Advisories

1
Debian
CVE-2015-8346: redmine - app/views/timelog/_form.html.erb in Redmine before 2.6.8, 3.0.x before 3.0.6, an...2015