Debian Redmine vulnerabilities
47 known vulnerabilities affecting debian/redmine.
Total CVEs
47
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH9MEDIUM35LOW2
Vulnerabilities
Page 2 of 3
CVE-2017-15574P4MEDIUMCVSS 6.1fixed in redmine 3.4.2-1 (bookworm)2017
CVE-2017-15574 [MEDIUM] CVE-2017-15574: redmine - In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using ...
In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using an SVG document as an attachment.
Scope: local
bookworm: resolved (fixed in 3.4.2-1)
sid: resolved (fixed in 3.4.2-1)
trixie: resolved (fixed in 3.4.2-1)
debian
CVE-2020-36306P4MEDIUMCVSS 6.1fixed in redmine 4.0.7-1 (bookworm)2020
CVE-2020-36306 [MEDIUM] CVE-2020-36306: redmine - Redmine before 4.0.7 and 4.1.x before 4.1.1 has XSS via the back_url field.
Redmine before 4.0.7 and 4.1.x before 4.1.1 has XSS via the back_url field.
Scope: local
bookworm: resolved (fixed in 4.0.7-1)
sid: resolved (fixed in 4.0.7-1)
trixie: resolved (fixed in 4.0.7-1)
debian
CVE-2020-36307P4MEDIUMCVSS 6.1fixed in redmine 4.0.7-1 (bookworm)2020
CVE-2020-36307 [MEDIUM] CVE-2020-36307: redmine - Redmine before 4.0.7 and 4.1.x before 4.1.1 has stored XSS via textile inline li...
Redmine before 4.0.7 and 4.1.x before 4.1.1 has stored XSS via textile inline links.
Scope: local
bookworm: resolved (fixed in 4.0.7-1)
sid: resolved (fixed in 4.0.7-1)
trixie: resolved (fixed in 4.0.7-1)
debian
CVE-2022-44031P4MEDIUMCVSS 6.1fixed in redmine 5.0.4-1 (bookworm)2022
CVE-2022-44031 [MEDIUM] CVE-2022-44031: redmine - Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile...
Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization of the blockquote syntax in Textile-formatted fields.
Scope: local
bookworm: resolved (fixed in 5.0.4-1)
sid: resolved (fixed in 5.0.4-1)
trixie: resolved (fixed in 5.0.4-1)
debian
CVE-2023-47259P4MEDIUMCVSS 6.1fixed in redmine 5.0.4-5+deb12u1 (bookworm)2023
CVE-2023-47259 [MEDIUM] CVE-2023-47259: redmine - Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in the Textile formatter...
Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in the Textile formatter.
Scope: local
bookworm: resolved (fixed in 5.0.4-5+deb12u1)
sid: resolved (fixed in 5.1.3+ds-1)
trixie: resolved (fixed in 5.1.3+ds-1)
debian
CVE-2023-47258P4MEDIUMCVSS 6.1fixed in redmine 5.0.4-5+deb12u1 (bookworm)2023
CVE-2023-47258 [MEDIUM] CVE-2023-47258: redmine - Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in a Markdown formatter.
Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in a Markdown formatter.
Scope: local
bookworm: resolved (fixed in 5.0.4-5+deb12u1)
sid: resolved (fixed in 5.1.3+ds-1)
trixie: resolved (fixed in 5.1.3+ds-1)
debian
CVE-2023-47260P4MEDIUMCVSS 6.1fixed in redmine 5.0.4-5+deb12u1 (bookworm)2023
CVE-2023-47260 [MEDIUM] CVE-2023-47260: redmine - Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS via thumbnails.
Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS via thumbnails.
Scope: local
bookworm: resolved (fixed in 5.0.4-5+deb12u1)
sid: resolved (fixed in 5.1.3+ds-1)
trixie: resolved (fixed in 5.1.3+ds-1)
debian
CVE-2015-8537P4MEDIUMCVSS 5.3fixed in redmine 3.2.0-1 (bookworm)2015
CVE-2015-8537 [MEDIUM] CVE-2015-8537: redmine - app/views/journals/index.builder in Redmine before 2.6.9, 3.0.x before 3.0.7, an...
app/views/journals/index.builder in Redmine before 2.6.9, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote attackers to obtain sensitive information by viewing an Atom feed.
Scope: local
bookworm: resolved (fixed in 3.2.0-1)
sid: resolved (fixed in 3.2.0-1)
trixie: resolved (fixed in 3.2.0-1)
debian
CVE-2015-8346P4MEDIUMCVSS 5.3fixed in redmine 3.2.0-1 (bookworm)2015
CVE-2015-8346 [MEDIUM] CVE-2015-8346: redmine - app/views/timelog/_form.html.erb in Redmine before 2.6.8, 3.0.x before 3.0.6, an...
app/views/timelog/_form.html.erb in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote attackers to obtain sensitive information about subjects of issues by viewing the time logging form.
Scope: local
bookworm: resolved (fixed in 3.2.0-1)
sid: resolved (fixed in 3.2.0-1)
trixie: resolved (fixed in 3.2.0-1)
debian
CVE-2021-31865P4MEDIUMCVSS 5.3fixed in redmine 5.0.0-1 (bookworm)2021
CVE-2021-31865 [MEDIUM] CVE-2021-31865: redmine - Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows users to...
Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows users to circumvent the allowed filename extensions of uploaded attachments.
Scope: local
bookworm: resolved (fixed in 5.0.0-1)
sid: resolved (fixed in 5.0.0-1)
trixie: resolved (fixed in 5.0.0-1)
debian
CVE-2020-36308P4MEDIUMCVSS 5.3fixed in redmine 4.0.7-1 (bookworm)2020
CVE-2020-36308 [MEDIUM] CVE-2020-36308: redmine - Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the sub...
Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performing a CSV export and reading time entries.
Scope: local
bookworm: resolved (fixed in 4.0.7-1)
sid: resolved (fixed in 4.0.7-1)
trixie: resolved (fixed in 4.0.7-1)
debian
CVE-2012-2054P4MEDIUMCVSS 4.3fixed in redmine 1.3.2+dfsg1-1 (bookworm)2012
CVE-2012-2054 [MEDIUM] CVE-2012-2054: redmine - Redmine before 1.3.2 does not properly restrict the use of a hash to provide val...
Redmine before 1.3.2 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set attributes in the (1) Comment, (2) Document, (3) IssueCategory, (4) MembersController, (5) Message, (6) News, (7) TimeEntry, (8) Version, (9) Wiki, (10) UserPreference, or (11) Board model via a modified URL, related to a
debian
CVE-2017-15570P4MEDIUMCVSS 6.1fixed in redmine 3.4.4-1 (bookworm)2017
CVE-2017-15570 [MEDIUM] CVE-2017-15570: redmine - In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists ...
In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/timelog/_list.html.erb via crafted column data.
Scope: local
bookworm: resolved (fixed in 3.4.4-1)
sid: resolved (fixed in 3.4.4-1)
trixie: resolved (fixed in 3.4.4-1)
debian
CVE-2017-15573P4MEDIUMCVSS 6.1fixed in redmine 3.4.2-1 (bookworm)2017
CVE-2017-15573 [MEDIUM] CVE-2017-15573: redmine - In Redmine before 3.2.6 and 3.3.x before 3.3.3, XSS exists because markup is mis...
In Redmine before 3.2.6 and 3.3.x before 3.3.3, XSS exists because markup is mishandled in wiki content.
Scope: local
bookworm: resolved (fixed in 3.4.2-1)
sid: resolved (fixed in 3.4.2-1)
trixie: resolved (fixed in 3.4.2-1)
debian
CVE-2016-10515P4MEDIUMCVSS 6.1fixed in redmine 3.2.3-1 (bookworm)2016
CVE-2016-10515 [MEDIUM] CVE-2016-10515: redmine - In Redmine before 3.2.3, there are stored XSS vulnerabilities affecting Textile ...
In Redmine before 3.2.3, there are stored XSS vulnerabilities affecting Textile and Markdown text formatting, and project homepages.
Scope: local
bookworm: resolved (fixed in 3.2.3-1)
sid: resolved (fixed in 3.2.3-1)
trixie: resolved (fixed in 3.2.3-1)
debian
CVE-2017-15571P4MEDIUMCVSS 6.1fixed in redmine 3.4.4-1 (bookworm)2017
CVE-2017-15571 [MEDIUM] CVE-2017-15571: redmine - In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists ...
In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/issues/_list.html.erb via crafted column data.
Scope: local
bookworm: resolved (fixed in 3.4.4-1)
sid: resolved (fixed in 3.4.4-1)
trixie: resolved (fixed in 3.4.4-1)
debian
CVE-2017-15569P4MEDIUMCVSS 6.1fixed in redmine 3.4.4-1 (bookworm)2017
CVE-2017-15569 [MEDIUM] CVE-2017-15569: redmine - In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists ...
In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/queries_helper.rb via a multi-value field with a crafted value that is mishandled during rendering of an issue list.
Scope: local
bookworm: resolved (fixed in 3.4.4-1)
sid: resolved (fixed in 3.4.4-1)
trixie: resolved (fixed in 3.4.4-1)
debian
CVE-2017-15568P4MEDIUMCVSS 6.1fixed in redmine 3.4.4-1 (bookworm)2017
CVE-2017-15568 [MEDIUM] CVE-2017-15568: redmine - In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists ...
In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/application_helper.rb via a multi-value field with a crafted value that is mishandled during rendering of issue history.
Scope: local
bookworm: resolved (fixed in 3.4.4-1)
sid: resolved (fixed in 3.4.4-1)
trixie: resolved (fixed in 3.4.4-1)
debian
CVE-2015-8473P4MEDIUMCVSS 4.3fixed in redmine 3.2.0-1 (bookworm)2015
CVE-2015-8473 [MEDIUM] CVE-2015-8473: redmine - The Issues API in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1...
The Issues API in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote authenticated users to obtain sensitive information in changeset messages by leveraging permission to read issues with related changesets from other projects.
Scope: local
bookworm: resolved (fixed in 3.2.0-1)
sid: resolved (fixed in 3.2.0-1)
trixie: resolved (fixed in 3
debian
CVE-2014-1985P4MEDIUMCVSS 5.8fixed in redmine 2.5.1-1 (bookworm)2014
CVE-2014-1985 [MEDIUM] CVE-2014-1985: redmine - Open redirect vulnerability in the redirect_back_or_default function in app/cont...
Open redirect vulnerability in the redirect_back_or_default function in app/controllers/application_controller.rb in Redmine before 2.4.5 and 2.5.x before 2.5.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the back url (back_url parameter).
Scope: local
bookworm: resolved (fixed in 2.5.1-1)
sid: resolved
debian