Debian Redmine vulnerabilities
47 known vulnerabilities affecting debian/redmine.
Total CVEs
47
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH9MEDIUM35LOW2
Vulnerabilities
Page 1 of 3
CVE-2011-4929P2HIGHCVSS 7.5PoCfixed in redmine 1.0.5-1 (bookworm)2011
CVE-2011-4929 [HIGH] CVE-2011-4929: redmine - Unspecified vulnerability in the bazaar repository adapter in Redmine 0.9.x and ...
Unspecified vulnerability in the bazaar repository adapter in Redmine 0.9.x and 1.0.x before 1.0.5 allows remote attackers to execute arbitrary commands via unknown vectors.
Scope: local
bookworm: resolved (fixed in 1.0.5-1)
sid: resolved (fixed in 1.0.5-1)
trixie: resolved (fixed in 1.0.5-1)
debian
CVE-2017-18026P3HIGHCVSS 8.8fixed in redmine 3.4.4-1 (bookworm)2017
CVE-2017-18026 [HIGH] CVE-2017-18026: redmine - Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block ...
Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary commands (through the Mercurial adapter) via vectors involving a branch whose name begins with a --config= or --debugger= substring, a related issue to CVE-2017-17536.
Scope:
debian
CVE-2021-30164P3CRITICALCVSS 9.8fixed in redmine 5.0.0-1 (bookworm)2021
CVE-2021-30164 [CRITICAL] CVE-2021-30164: redmine - Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_i...
Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_issue_notes permission requirement by leveraging the Issues API.
Scope: local
bookworm: resolved (fixed in 5.0.0-1)
sid: resolved (fixed in 5.0.0-1)
trixie: resolved (fixed in 5.0.0-1)
debian
CVE-2021-31863P3HIGHCVSS 7.5fixed in redmine 5.0.0-1 (bookworm)2021
CVE-2021-31863 [HIGH] CVE-2021-31863: redmine - Insufficient input validation in the Git repository integration of Redmine befor...
Insufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows Redmine users to read arbitrary local files accessible by the application server process.
Scope: local
bookworm: resolved (fixed in 5.0.0-1)
sid: resolved (fixed in 5.0.0-1)
trixie: resolved (fixed in 5.0.0-1)
debian
CVE-2019-18890P3MEDIUMCVSS 6.5fixed in redmine 3.4.2-1 (bookworm)2019
CVE-2019-18890 [MEDIUM] CVE-2019-18890: redmine - A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 a...
A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crafted object query.
Scope: local
bookworm: resolved (fixed in 3.4.2-1)
sid: resolved (fixed in 3.4.2-1)
trixie: resolved (fixed in 3.4.2-1)
debian
CVE-2022-44030P3HIGHCVSS 7.5fixed in redmine 5.0.4-1 (bookworm)2022
CVE-2022-44030 [HIGH] CVE-2022-44030: redmine - Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or ...
Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the configuration, this may require login as a registered user.
Scope: local
bookworm: resolved (fixed in 5.0.4-1)
sid: resolved (fixed in 5.0.4-1)
trixie: resolved (fixed in 5.0.4-1)
debian
CVE-2017-15572P3HIGHCVSS 7.5fixed in redmine 3.4.2-1 (bookworm)2017
CVE-2017-15572 [HIGH] CVE-2017-15572: redmine - In Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sens...
In Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sensitive information (password reset tokens) by reading a Referer log, because account/lost_password does not use a redirect.
Scope: local
bookworm: resolved (fixed in 3.4.2-1)
sid: resolved (fixed in 3.4.2-1)
trixie: resolved (fixed in 3.4.2-1)
debian
CVE-2021-30163P3HIGHCVSS 7.5fixed in redmine 5.0.0-1 (bookworm)2021
CVE-2021-30163 [HIGH] CVE-2021-30163: redmine - Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the nam...
Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the names of private projects if issue-journal details exist that have changes to project_id values.
Scope: local
bookworm: resolved (fixed in 5.0.0-1)
sid: resolved (fixed in 5.0.0-1)
trixie: resolved (fixed in 5.0.0-1)
debian
CVE-2017-15577P3HIGHCVSS 7.5fixed in redmine 3.4.2-1 (bookworm)2017
CVE-2017-15577 [HIGH] CVE-2017-15577: redmine - Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki lin...
Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows remote attackers to obtain sensitive information.
Scope: local
bookworm: resolved (fixed in 3.4.2-1)
sid: resolved (fixed in 3.4.2-1)
trixie: resolved (fixed in 3.4.2-1)
debian
CVE-2017-15576P3HIGHCVSS 7.5fixed in redmine 3.4.2-1 (bookworm)2017
CVE-2017-15576 [HIGH] CVE-2017-15576: redmine - Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in a...
Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensitive information.
Scope: local
bookworm: resolved (fixed in 3.4.2-1)
sid: resolved (fixed in 3.4.2-1)
trixie: resolved (fixed in 3.4.2-1)
debian
CVE-2017-15575P3HIGHCVSS 7.3fixed in redmine 3.4.2-1 (bookworm)2017
CVE-2017-15575 [HIGH] CVE-2017-15575: redmine - In Redmine before 3.2.6 and 3.3.x before 3.3.3, Redmine.pm lacks a check for whe...
In Redmine before 3.2.6 and 3.3.x before 3.3.3, Redmine.pm lacks a check for whether the Repository module is enabled in a project's settings, which might allow remote attackers to obtain sensitive differences information or possibly have unspecified other impact.
Scope: local
bookworm: resolved (fixed in 3.4.2-1)
sid: resolved (fixed in 3.4.2-1)
trixie: resolved (f
debian
CVE-2015-8474P4MEDIUMCVSS 5.8fixed in redmine 3.2.0-1 (bookworm)2015
CVE-2015-8474 [MEDIUM] CVE-2015-8474: redmine - Open redirect vulnerability in the valid_back_url function in app/controllers/ap...
Open redirect vulnerability in the valid_back_url function in app/controllers/application_controller.rb in Redmine before 2.6.7, 3.0.x before 3.0.5, and 3.1.x before 3.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted back_url parameter, as demonstrated by "@attacker.com," a different vulnerability than C
debian
CVE-2021-31866P4MEDIUMCVSS 5.3fixed in redmine 5.0.0-1 (bookworm)2021
CVE-2021-31866 [MEDIUM] CVE-2021-31866: redmine - Redmine before 4.0.9 and 4.1.x before 4.1.3 allows an attacker to learn the valu...
Redmine before 4.0.9 and 4.1.x before 4.1.3 allows an attacker to learn the values of internal authentication keys by observing timing differences in string comparison operations within SysController and MailHandlerController.
Scope: local
bookworm: resolved (fixed in 5.0.0-1)
sid: resolved (fixed in 5.0.0-1)
trixie: resolved (fixed in 5.0.0-1)
debian
CVE-2021-31864P4MEDIUMCVSS 5.3fixed in redmine 5.0.0-1 (bookworm)2021
CVE-2021-31864 [MEDIUM] CVE-2021-31864: redmine - Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows attacker...
Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows attackers to bypass the add_issue_notes permission requirement by leveraging the incoming mail handler.
Scope: local
bookworm: resolved (fixed in 5.0.0-1)
sid: resolved (fixed in 5.0.0-1)
trixie: resolved (fixed in 5.0.0-1)
debian
CVE-2019-17427P4MEDIUMCVSS 6.1fixed in redmine 4.0.4-1 (bookworm)2019
CVE-2019-17427 [MEDIUM] CVE-2019-17427: redmine - In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to te...
In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.
Scope: local
bookworm: resolved (fixed in 4.0.4-1)
sid: resolved (fixed in 4.0.4-1)
trixie: resolved (fixed in 4.0.4-1)
debian
CVE-2021-42326P4MEDIUMCVSS 5.3fixed in redmine 5.0.0-1 (bookworm)2021
CVE-2021-42326 [MEDIUM] CVE-2021-42326: redmine - Redmine before 4.1.5 and 4.2.x before 4.2.3 may disclose the names of users on a...
Redmine before 4.1.5 and 4.2.x before 4.2.3 may disclose the names of users on activity views due to an insufficient access filter.
Scope: local
bookworm: resolved (fixed in 5.0.0-1)
sid: resolved (fixed in 5.0.0-1)
trixie: resolved (fixed in 5.0.0-1)
debian
CVE-2019-25026P4MEDIUMCVSS 5.3fixed in redmine 4.0.6-1 (bookworm)2019
CVE-2019-25026 [MEDIUM] CVE-2019-25026: redmine - Redmine before 3.4.13 and 4.x before 4.0.6 mishandles markup data during Textile...
Redmine before 3.4.13 and 4.x before 4.0.6 mishandles markup data during Textile formatting.
Scope: local
bookworm: resolved (fixed in 4.0.6-1)
sid: resolved (fixed in 4.0.6-1)
trixie: resolved (fixed in 4.0.6-1)
debian
CVE-2022-44637P4MEDIUMCVSS 6.1fixed in redmine 5.0.4-1 (bookworm)2022
CVE-2022-44637 [MEDIUM] CVE-2022-44637: redmine - Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile...
Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization in Redcloth3 Textile-formatted fields. Depending on the configuration, this may require login as a registered user.
Scope: local
bookworm: resolved (fixed in 5.0.4-1)
sid: resolved (fixed in 5.0.4-1)
trixie: resolved (fixed in 5.0.4-1)
debian
CVE-2009-4079P4MEDIUMCVSS 6.8fixed in redmine 0.9.0~svn2902-1 (bookworm)2009
CVE-2009-4079 [MEDIUM] CVE-2009-4079: redmine - Cross-site request forgery (CSRF) vulnerability in Redmine 0.8.5 and earlier all...
Cross-site request forgery (CSRF) vulnerability in Redmine 0.8.5 and earlier allows remote attackers to hijack the authentication of users for requests that delete a ticket via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 0.9.0~svn2902-1)
sid: resolved (fixed in 0.9.0~svn2902-1)
trixie: resolved (fixed in 0.9.0~svn2902-1)
debian
CVE-2015-8477P4LOWCVSS 6.1fixed in redmine 3.0~20140825-5 (bookworm)2015
CVE-2015-8477 [MEDIUM] CVE-2015-8477: redmine - Cross-site scripting (XSS) vulnerability in Redmine before 2.6.2 allows remote a...
Cross-site scripting (XSS) vulnerability in Redmine before 2.6.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving flash message rendering.
Scope: local
bookworm: resolved (fixed in 3.0~20140825-5)
sid: resolved (fixed in 3.0~20140825-5)
trixie: resolved (fixed in 3.0~20140825-5)
debian
1 / 3Next →