cbcvebase.

Debian Redmine vulnerabilities

47 known vulnerabilities affecting debian/redmine.

Total CVEs
47
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH9MEDIUM35LOW2

Vulnerabilities

Page 3 of 3
CVE-2017-16804P4MEDIUMCVSS 4.3fixed in redmine 3.4.2-1 (bookworm)2017
CVE-2017-16804 [MEDIUM] CVE-2017-16804: redmine - In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function in app/mo... In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function in app/models/mailer.rb does not check whether an issue is visible, which allows remote authenticated users to obtain sensitive information by reading e-mail reminder messages. Scope: local bookworm: resolved (fixed in 3.4.2-1) sid: resolved (fixed in 3.4.2-1) trixie: resolved (fixed in 3.4.2-1
debian
CVE-2011-4928P4MEDIUMCVSS 4.3fixed in redmine 1.0.5-1 (bookworm)2011
CVE-2011-4928 [MEDIUM] CVE-2011-4928: redmine - Cross-site scripting (XSS) vulnerability in the textile formatter in Redmine bef... Cross-site scripting (XSS) vulnerability in the textile formatter in Redmine before 1.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Scope: local bookworm: resolved (fixed in 1.0.5-1) sid: resolved (fixed in 1.0.5-1) trixie: resolved (fixed in 1.0.5-1)
debian
CVE-2012-0327P4MEDIUMCVSS 4.3fixed in redmine 1.3.2+dfsg1-1 (bookworm)2012
CVE-2012-0327 [MEDIUM] CVE-2012-0327: redmine - Cross-site scripting (XSS) vulnerability in Redmine before 1.3.2 allows remote a... Cross-site scripting (XSS) vulnerability in Redmine before 1.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Scope: local bookworm: resolved (fixed in 1.3.2+dfsg1-1) sid: resolved (fixed in 1.3.2+dfsg1-1) trixie: resolved (fixed in 1.3.2+dfsg1-1)
debian
CVE-2009-4078P4MEDIUMCVSS 4.3fixed in redmine 0.9.0~svn2902-1 (bookworm)2009
CVE-2009-4078 [MEDIUM] CVE-2009-4078: redmine - Multiple cross-site scripting (XSS) vulnerabilities in Redmine 0.8.5 and earlier... Multiple cross-site scripting (XSS) vulnerabilities in Redmine 0.8.5 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. Scope: local bookworm: resolved (fixed in 0.9.0~svn2902-1) sid: resolved (fixed in 0.9.0~svn2902-1) trixie: resolved (fixed in 0.9.0~svn2902-1)
debian
CVE-2025-4011P4LOWCVSS 5.1fixed in redmine 6.0.4+ds-1 (sid)2025
CVE-2025-4011 [MEDIUM] CVE-2025-4011: redmine - A vulnerability has been found in Redmine 6.0.0/6.0.1/6.0.2/6.0.3 and classified... A vulnerability has been found in Redmine 6.0.0/6.0.1/6.0.2/6.0.3 and classified as problematic. This vulnerability affects unknown code of the component Custom Query Handler. The manipulation of the argument Name leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 6.0.4 is able to address this issue. It is recommended to upgrad
debian
CVE-2009-4459P4MEDIUMCVSS 4.3fixed in redmine 0.9.1-1 (bookworm)2009
CVE-2009-4459 [MEDIUM] CVE-2009-4459: redmine - Redmine 0.8.7 and earlier uses the title tag before defining the character encod... Redmine 0.8.7 and earlier uses the title tag before defining the character encoding in a meta tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks and inject arbitrary script via UTF-7 encoded values in the title parameter to a new issue page, which may be interpreted as script by Internet Explorer 7 and 8. Scope: local bookworm: resolved
debian
CVE-2011-4927P4MEDIUMCVSS 4.0fixed in redmine 1.0.5-1 (bookworm)2011
CVE-2011-4927 [MEDIUM] CVE-2011-4927: redmine - Unspecified vulnerability in the bazaar repository adapter in Redmine 1.0.x befo... Unspecified vulnerability in the bazaar repository adapter in Redmine 1.0.x before 1.0.5 allows remote authenticated users to obtain sensitive information via unknown vectors. Scope: local bookworm: resolved (fixed in 1.0.5-1) sid: resolved (fixed in 1.0.5-1) trixie: resolved (fixed in 1.0.5-1)
debian
Debian Redmine vulnerabilities | cvebase