Перейти к содержимому
Noroxi

Записи Redmine

51 опубликованных записей вендора redmine.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
1 · 2 %
Pre-auth RCE
3
С записью об исправлении
90,2 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

51 записей
  • CVE-2011-4929
    44В плане

    Unspecified vulnerability in the bazaar repository adapter in Redmine 0.9.x and 1.0.x before 1.0.5 allows remote attackers to execute arbitr

    ВысокаяCVSS 7,5Готовый эксплойтEPSS 46 %

    redmine · redmine8 окт. 2012 г.

  • CVE-2021-30164
    39Наблюдать

    Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_issue_notes permission requirement by leveraging the Issues A

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    redmine · redmine6 апр. 2021 г.

  • CVE-2017-18026
    36Наблюдать

    Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg progra

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    redmine · redmine10 янв. 2018 г.

  • CVE-2017-15572
    31Наблюдать

    In Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sensitive information (password reset tokens) by reading a Refer

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    redmine · redmine17 окт. 2017 г.

  • CVE-2013-4663
    31Наблюдать

    git_http_controller.rb in the redmine_git_hosting plugin for Redmine allows remote attackers to execute arbitrary commands via shell metacha

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    redmine · redmine git hosting plugin27 дек. 2014 г.

  • CVE-2021-31863
    31Наблюдать

    Insufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows R

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    redmine · redmine28 апр. 2021 г.

  • CVE-2015-8474
    30Наблюдать

    Open redirect vulnerability in the valid_back_url function in app/controllers/application_controller.rb in Redmine before 2.6.7, 3.0.x befor

    ВысокаяCVSS 7,4Эксплойта нетEPSS 2 %

    redmine · redmine12 апр. 2016 г.

  • CVE-2017-15576
    30Наблюдать

    Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensi

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    redmine · redmine17 окт. 2017 г.

  • CVE-2017-15577
    30Наблюдать

    Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows remote attackers to obtain sensitive inform

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    redmine · redmine17 окт. 2017 г.

  • CVE-2021-30163
    30Наблюдать

    Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the names of private projects if issue-journal details exist that h

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    redmine · redmine6 апр. 2021 г.

  • CVE-2021-37156
    30Наблюдать

    Redmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling two-factor authentication for the user's account, but the int

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    redmine · redmine5 авг. 2021 г.

  • CVE-2022-44030
    30Наблюдать

    Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    redmine · redmine6 дек. 2022 г.

  • CVE-2017-15575
    29Наблюдать

    In Redmine before 3.2.6 and 3.3.x before 3.3.3, Redmine.pm lacks a check for whether the Repository module is enabled in a project's setting

    ВысокаяCVSS 7,3Эксплойта нетEPSS 1 %

    redmine · redmine17 окт. 2017 г.

  • CVE-2019-18890
    27Наблюдать

    A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a cr

    СредняяCVSS 6,5Proof of conceptEPSS 4 %

    redmine · redmine21 нояб. 2019 г.

  • CVE-2009-4079
    27Наблюдать

    Cross-site request forgery (CSRF) vulnerability in Redmine 0.8.5 and earlier allows remote attackers to hijack the authentication of users f

    СредняяCVSS 6,8Эксплойта нетEPSS 1 %

    redmine · redmine25 нояб. 2009 г.

  • CVE-2014-1985
    24Наблюдать

    Open redirect vulnerability in the redirect_back_or_default function in app/controllers/application_controller.rb in Redmine before 2.4.5 an

    СредняяCVSS 5,8Эксплойта нетEPSS 3 %

    redmine · redmine11 апр. 2014 г.

  • CVE-2019-17427
    24Наблюдать

    In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.

    СредняяCVSS 6,1Proof of conceptEPSS 2 %

    redmine · redmine9 окт. 2019 г.

  • CVE-2015-8477
    24Наблюдать

    Cross-site scripting (XSS) vulnerability in Redmine before 2.6.2 allows remote attackers to inject arbitrary web script or HTML via vectors

    СредняяCVSS 6,1Эксплойта нетEPSS 2 %

    redmine · redmine23 мая 2017 г.

  • CVE-2017-15573
    24Наблюдать

    In Redmine before 3.2.6 and 3.3.x before 3.3.3, XSS exists because markup is mishandled in wiki content.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    redmine · redmine17 окт. 2017 г.

  • CVE-2017-15571
    24Наблюдать

    In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/issues/_list.html.erb via crafted column data.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    redmine · redmine17 окт. 2017 г.

  • CVE-2017-15570
    24Наблюдать

    In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/timelog/_list.html.erb via crafted column data.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    redmine · redmine17 окт. 2017 г.

  • CVE-2017-15574
    24Наблюдать

    In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using an SVG document as an attachment.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    redmine · redmine17 окт. 2017 г.

  • CVE-2017-15568
    24Наблюдать

    In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/application_helper.rb via a multi-value field

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    redmine · redmine17 окт. 2017 г.

  • CVE-2017-15569
    24Наблюдать

    In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/queries_helper.rb via a multi-value field wit

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    redmine · redmine17 окт. 2017 г.

  • CVE-2021-29274
    24Наблюдать

    Redmine 4.1.x before 4.1.2 allows XSS because an issue's subject is mishandled in the auto complete tip.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    redmine · redmine29 мар. 2021 г.