CVE-2019-18890
published 2019-11-21CVE-2019-18890: A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crafted object query.
PriorityP341medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
4.34%
90.1th percentile
A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crafted object query.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | redmine | < redmine 3.4.2-1 (bookworm) | redmine 3.4.2-1 (bookworm) |
| redmine | redmine | < 3.3.10 | 3.3.10 |
| redmine | redmine | >= 0 < 3.4.2-1 | 3.4.2-1 |
| redmine | redmine | >= 0 < 3.4.2-1 | 3.4.2-1 |
| redmine | redmine | >= 0 < 3.2.1-2ubuntu0.2 | 3.2.1-2ubuntu0.2 |
| redmine | redmine | >= 0 < 3.4.4-1ubuntu0.1 | 3.4.4-1ubuntu0.1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_ubuntu6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Redmine vulnerabilities
vendor_ubuntu·2019-11-26·CVSS 6.1
CVE-2019-17427 [MEDIUM] Redmine vulnerabilities
Title: Redmine vulnerabilities
Summary: Several security issues were fixed in redmine.
It was discovered that Redmine incorrectly handle certain inputs that could
cause textile formatting errors. An attacker could possibly use this issue to
cause a XSS attack. (CVE-2019-17427)
It was discovered that an SQL injection could allow users to access protected
information via a crafted object query. (CVE-2019-18890)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2019-18890: redmine - A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 a...
vendor_debian·2019·CVSS 6.5
CVE-2019-18890 [MEDIUM] CVE-2019-18890: redmine - A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 a...
A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crafted object query.
Scope: local
bookworm: resolved (fixed in 3.4.2-1)
sid: resolved (fixed in 3.4.2-1)
trixie: resolved (fixed in 3.4.2-1)
GHSA
GHSA-79wp-q4g4-2m5r: A SQL injection vulnerability in Redmine through 3
ghsa_unreviewed·2022-05-24
CVE-2019-18890 [MEDIUM] GHSA-79wp-q4g4-2m5r: A SQL injection vulnerability in Redmine through 3
A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crafted object query.
OSV
redmine vulnerabilities
osv·2019-11-26·CVSS 6.1
CVE-2019-17427 [MEDIUM] redmine vulnerabilities
redmine vulnerabilities
It was discovered that Redmine incorrectly handle certain inputs that could
cause textile formatting errors. An attacker could possibly use this issue to
cause a XSS attack. (CVE-2019-17427)
It was discovered that an SQL injection could allow users to access protected
information via a crafted object query. (CVE-2019-18890)
OSV
CVE-2019-18890: A SQL injection vulnerability in Redmine through 3
osv·2019-11-21·CVSS 6.5
CVE-2019-18890 [MEDIUM] CVE-2019-18890: A SQL injection vulnerability in Redmine through 3
A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crafted object query.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/RealLinkers/CVE-2019-18890https://seclists.org/bugtraq/2019/Nov/31https://security-tracker.debian.org/tracker/CVE-2019-18890https://usn.ubuntu.com/4200-1/https://www.debian.org/security/2019/dsa-4574https://www.debian.org/security/2019/dsa-4574https://www.redmine.org/projects/redmine/wiki/Security_Advisorieshttps://github.com/RealLinkers/CVE-2019-18890https://seclists.org/bugtraq/2019/Nov/31https://security-tracker.debian.org/tracker/CVE-2019-18890https://usn.ubuntu.com/4200-1/https://www.debian.org/security/2019/dsa-4574https://www.debian.org/security/2019/dsa-4574https://www.redmine.org/projects/redmine/wiki/Security_Advisories
2019-11-21
Published