CVE-2019-17427
published 2019-10-10CVE-2019-17427: In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.
PriorityP427medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.60%
72.9th percentile
In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | redmine | < redmine 4.0.4-1 (bookworm) | redmine 4.0.4-1 (bookworm) |
| redmine | redmine | < 3.4.11 | 3.4.11 |
| redmine | redmine | >= 0 < 4.0.4-1 | 4.0.4-1 |
| redmine | redmine | >= 0 < 4.0.4-1 | 4.0.4-1 |
| redmine | redmine | >= 0 < 3.2.1-2ubuntu0.2 | 3.2.1-2ubuntu0.2 |
| redmine | redmine | >= 0 < 3.4.4-1ubuntu0.1 | 3.4.4-1ubuntu0.1 |
| redmine | redmine | >= 4.0.0 < 4.0.4 | 4.0.4 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_ubuntu6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Redmine vulnerabilities
vendor_ubuntu·2019-11-26·CVSS 6.1
CVE-2019-17427 [MEDIUM] Redmine vulnerabilities
Title: Redmine vulnerabilities
Summary: Several security issues were fixed in redmine.
It was discovered that Redmine incorrectly handle certain inputs that could
cause textile formatting errors. An attacker could possibly use this issue to
cause a XSS attack. (CVE-2019-17427)
It was discovered that an SQL injection could allow users to access protected
information via a crafted object query. (CVE-2019-18890)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2019-17427: redmine - In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to te...
vendor_debian·2019·CVSS 6.1
CVE-2019-17427 [MEDIUM] CVE-2019-17427: redmine - In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to te...
In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.
Scope: local
bookworm: resolved (fixed in 4.0.4-1)
sid: resolved (fixed in 4.0.4-1)
trixie: resolved (fixed in 4.0.4-1)
GHSA
GHSA-g969-264w-g9pr: In Redmine before 3
ghsa_unreviewed·2022-05-24
CVE-2019-17427 [MEDIUM] GHSA-g969-264w-g9pr: In Redmine before 3
In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.
OSV
redmine vulnerabilities
osv·2019-11-26·CVSS 6.1
CVE-2019-17427 [MEDIUM] redmine vulnerabilities
redmine vulnerabilities
It was discovered that Redmine incorrectly handle certain inputs that could
cause textile formatting errors. An attacker could possibly use this issue to
cause a XSS attack. (CVE-2019-17427)
It was discovered that an SQL injection could allow users to access protected
information via a crafted object query. (CVE-2019-18890)
OSV
CVE-2019-17427: In Redmine before 3
osv·2019-10-10·CVSS 6.1
CVE-2019-17427 [MEDIUM] CVE-2019-17427: In Redmine before 3
In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/RealLinkers/CVE-2019-17427https://seclists.org/bugtraq/2019/Nov/31https://usn.ubuntu.com/4200-1/https://www.debian.org/security/2019/dsa-4574https://www.redmine.org/projects/redmine/wiki/Security_Advisorieshttps://github.com/RealLinkers/CVE-2019-17427https://seclists.org/bugtraq/2019/Nov/31https://usn.ubuntu.com/4200-1/https://www.debian.org/security/2019/dsa-4574https://www.redmine.org/projects/redmine/wiki/Security_Advisories
2019-10-10
Published