CVE-2017-16804Sensitive Information Exposure in Redmine

Severity
4.3MEDIUMNVD
EPSS
0.3%
top 42.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 13
Latest updateMay 14

Description

In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function in app/models/mailer.rb does not check whether an issue is visible, which allows remote authenticated users to obtain sensitive information by reading e-mail reminder messages.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages3 packages

debiandebian/redmine< redmine 3.4.2-1 (bookworm)
NVDredmine/redmine< 3.2.7+4
Debianredmine/redmine< 3.4.2-1+1

Also affects: Debian Linux 9.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-c2rv-c7wr-4chh: In Redmine before 32022-05-14
OSV
CVE-2017-16804: In Redmine before 32017-11-13

📋Vendor Advisories

1
Debian
CVE-2017-16804: redmine - In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function in app/mo...2017