Debian Redmine vulnerabilities
49 known vulnerabilities affecting debian/redmine.
Total CVEs
49
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH9MEDIUM35LOW4
Vulnerabilities
Page 1 of 3
CVE-2025-4011LOWCVSS 5.1fixed in redmine 6.0.4+ds-1 (sid)2025
CVE-2025-4011 [MEDIUM] CVE-2025-4011: redmine - A vulnerability has been found in Redmine 6.0.0/6.0.1/6.0.2/6.0.3 and classified...
A vulnerability has been found in Redmine 6.0.0/6.0.1/6.0.2/6.0.3 and classified as problematic. This vulnerability affects unknown code of the component Custom Query Handler. The manipulation of the argument Name leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 6.0.4 is able to address this issue. It is recommended to upgrad
debian
CVE-2023-47258MEDIUMCVSS 6.1fixed in redmine 5.0.4-5+deb12u1 (bookworm)2023
CVE-2023-47258 [MEDIUM] CVE-2023-47258: redmine - Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in a Markdown formatter.
Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in a Markdown formatter.
Scope: local
bookworm: resolved (fixed in 5.0.4-5+deb12u1)
sid: resolved (fixed in 5.1.3+ds-1)
trixie: resolved (fixed in 5.1.3+ds-1)
debian
CVE-2023-47259MEDIUMCVSS 6.1fixed in redmine 5.0.4-5+deb12u1 (bookworm)2023
CVE-2023-47259 [MEDIUM] CVE-2023-47259: redmine - Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in the Textile formatter...
Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in the Textile formatter.
Scope: local
bookworm: resolved (fixed in 5.0.4-5+deb12u1)
sid: resolved (fixed in 5.1.3+ds-1)
trixie: resolved (fixed in 5.1.3+ds-1)
debian
CVE-2023-47260MEDIUMCVSS 6.1fixed in redmine 5.0.4-5+deb12u1 (bookworm)2023
CVE-2023-47260 [MEDIUM] CVE-2023-47260: redmine - Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS via thumbnails.
Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS via thumbnails.
Scope: local
bookworm: resolved (fixed in 5.0.4-5+deb12u1)
sid: resolved (fixed in 5.1.3+ds-1)
trixie: resolved (fixed in 5.1.3+ds-1)
debian
CVE-2022-44030HIGHCVSS 7.5fixed in redmine 5.0.4-1 (bookworm)2022
CVE-2022-44030 [HIGH] CVE-2022-44030: redmine - Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or ...
Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the configuration, this may require login as a registered user.
Scope: local
bookworm: resolved (fixed in 5.0.4-1)
sid: resolved (fixed in 5.0.4-1)
trixie: resolved (fixed in 5.0.4-1)
debian
CVE-2022-44637MEDIUMCVSS 6.1fixed in redmine 5.0.4-1 (bookworm)2022
CVE-2022-44637 [MEDIUM] CVE-2022-44637: redmine - Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile...
Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization in Redcloth3 Textile-formatted fields. Depending on the configuration, this may require login as a registered user.
Scope: local
bookworm: resolved (fixed in 5.0.4-1)
sid: resolved (fixed in 5.0.4-1)
trixie: resolved (fixed in 5.0.4-1)
debian
CVE-2022-44031MEDIUMCVSS 6.1fixed in redmine 5.0.4-1 (bookworm)2022
CVE-2022-44031 [MEDIUM] CVE-2022-44031: redmine - Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile...
Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization of the blockquote syntax in Textile-formatted fields.
Scope: local
bookworm: resolved (fixed in 5.0.4-1)
sid: resolved (fixed in 5.0.4-1)
trixie: resolved (fixed in 5.0.4-1)
debian
CVE-2021-30164CRITICALCVSS 9.8fixed in redmine 5.0.0-1 (bookworm)2021
CVE-2021-30164 [CRITICAL] CVE-2021-30164: redmine - Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_i...
Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_issue_notes permission requirement by leveraging the Issues API.
Scope: local
bookworm: resolved (fixed in 5.0.0-1)
sid: resolved (fixed in 5.0.0-1)
trixie: resolved (fixed in 5.0.0-1)
debian
CVE-2021-30163HIGHCVSS 7.5fixed in redmine 5.0.0-1 (bookworm)2021
CVE-2021-30163 [HIGH] CVE-2021-30163: redmine - Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the nam...
Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the names of private projects if issue-journal details exist that have changes to project_id values.
Scope: local
bookworm: resolved (fixed in 5.0.0-1)
sid: resolved (fixed in 5.0.0-1)
trixie: resolved (fixed in 5.0.0-1)
debian
CVE-2021-31863HIGHCVSS 7.5fixed in redmine 5.0.0-1 (bookworm)2021
CVE-2021-31863 [HIGH] CVE-2021-31863: redmine - Insufficient input validation in the Git repository integration of Redmine befor...
Insufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows Redmine users to read arbitrary local files accessible by the application server process.
Scope: local
bookworm: resolved (fixed in 5.0.0-1)
sid: resolved (fixed in 5.0.0-1)
trixie: resolved (fixed in 5.0.0-1)
debian
CVE-2021-31866MEDIUMCVSS 5.3fixed in redmine 5.0.0-1 (bookworm)2021
CVE-2021-31866 [MEDIUM] CVE-2021-31866: redmine - Redmine before 4.0.9 and 4.1.x before 4.1.3 allows an attacker to learn the valu...
Redmine before 4.0.9 and 4.1.x before 4.1.3 allows an attacker to learn the values of internal authentication keys by observing timing differences in string comparison operations within SysController and MailHandlerController.
Scope: local
bookworm: resolved (fixed in 5.0.0-1)
sid: resolved (fixed in 5.0.0-1)
trixie: resolved (fixed in 5.0.0-1)
debian
CVE-2021-31865MEDIUMCVSS 5.3fixed in redmine 5.0.0-1 (bookworm)2021
CVE-2021-31865 [MEDIUM] CVE-2021-31865: redmine - Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows users to...
Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows users to circumvent the allowed filename extensions of uploaded attachments.
Scope: local
bookworm: resolved (fixed in 5.0.0-1)
sid: resolved (fixed in 5.0.0-1)
trixie: resolved (fixed in 5.0.0-1)
debian
CVE-2021-42326MEDIUMCVSS 5.3fixed in redmine 5.0.0-1 (bookworm)2021
CVE-2021-42326 [MEDIUM] CVE-2021-42326: redmine - Redmine before 4.1.5 and 4.2.x before 4.2.3 may disclose the names of users on a...
Redmine before 4.1.5 and 4.2.x before 4.2.3 may disclose the names of users on activity views due to an insufficient access filter.
Scope: local
bookworm: resolved (fixed in 5.0.0-1)
sid: resolved (fixed in 5.0.0-1)
trixie: resolved (fixed in 5.0.0-1)
debian
CVE-2021-31864MEDIUMCVSS 5.3fixed in redmine 5.0.0-1 (bookworm)2021
CVE-2021-31864 [MEDIUM] CVE-2021-31864: redmine - Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows attacker...
Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows attackers to bypass the add_issue_notes permission requirement by leveraging the incoming mail handler.
Scope: local
bookworm: resolved (fixed in 5.0.0-1)
sid: resolved (fixed in 5.0.0-1)
trixie: resolved (fixed in 5.0.0-1)
debian
CVE-2021-37156LOWCVSS 7.52021
CVE-2021-37156 [HIGH] CVE-2021-37156: redmine - Redmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling t...
Redmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling two-factor authentication for the user's account, but the intended behavior is for those sessions to be terminated.
Scope: local
bookworm: resolved
sid: resolved
trixie: resolved
debian
CVE-2021-29274LOWCVSS 6.12021
CVE-2021-29274 [MEDIUM] CVE-2021-29274: redmine - Redmine 4.1.x before 4.1.2 allows XSS because an issue's subject is mishandled i...
Redmine 4.1.x before 4.1.2 allows XSS because an issue's subject is mishandled in the auto complete tip.
Scope: local
bookworm: resolved
sid: resolved
trixie: resolved
debian
CVE-2020-36306MEDIUMCVSS 6.1fixed in redmine 4.0.7-1 (bookworm)2020
CVE-2020-36306 [MEDIUM] CVE-2020-36306: redmine - Redmine before 4.0.7 and 4.1.x before 4.1.1 has XSS via the back_url field.
Redmine before 4.0.7 and 4.1.x before 4.1.1 has XSS via the back_url field.
Scope: local
bookworm: resolved (fixed in 4.0.7-1)
sid: resolved (fixed in 4.0.7-1)
trixie: resolved (fixed in 4.0.7-1)
debian
CVE-2020-36308MEDIUMCVSS 5.3fixed in redmine 4.0.7-1 (bookworm)2020
CVE-2020-36308 [MEDIUM] CVE-2020-36308: redmine - Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the sub...
Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performing a CSV export and reading time entries.
Scope: local
bookworm: resolved (fixed in 4.0.7-1)
sid: resolved (fixed in 4.0.7-1)
trixie: resolved (fixed in 4.0.7-1)
debian
CVE-2020-36307MEDIUMCVSS 6.1fixed in redmine 4.0.7-1 (bookworm)2020
CVE-2020-36307 [MEDIUM] CVE-2020-36307: redmine - Redmine before 4.0.7 and 4.1.x before 4.1.1 has stored XSS via textile inline li...
Redmine before 4.0.7 and 4.1.x before 4.1.1 has stored XSS via textile inline links.
Scope: local
bookworm: resolved (fixed in 4.0.7-1)
sid: resolved (fixed in 4.0.7-1)
trixie: resolved (fixed in 4.0.7-1)
debian
CVE-2019-18890MEDIUMCVSS 6.5fixed in redmine 3.4.2-1 (bookworm)2019
CVE-2019-18890 [MEDIUM] CVE-2019-18890: redmine - A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 a...
A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crafted object query.
Scope: local
bookworm: resolved (fixed in 3.4.2-1)
sid: resolved (fixed in 3.4.2-1)
trixie: resolved (fixed in 3.4.2-1)
debian
1 / 3Next →