Записи Redmine
51 опубликованных записей вендора redmine.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 2 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 90,2 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')23
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-20 Improper Input Validation2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-532 Insertion of Sensitive Information into Log File1
- CWE-613 Insufficient Session Expiration1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
51 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
44В плане | CVE-2011-4929Готовый эксплойт | Unspecified vulnerability in the bazaar repository adapter in Redmine 0.9.x and 1.0.x before 1.0.5 allows remote attackers to execute arbitrredmine · redmine | Высокая7,5 | — | 46,4 % | 8 окт. 2012 г. |
39Наблюдать | CVE-2021-30164Эксплойта нет | Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_issue_notes permission requirement by leveraging the Issues Aredmine · redmine | Критическая9,8 | — | 1,3 % | 6 апр. 2021 г. |
36Наблюдать | CVE-2017-18026Эксплойта нет | Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg prograredmine · redmine | Высокая8,8 | — | 2,8 % | 10 янв. 2018 г. |
31Наблюдать | CVE-2017-15572Эксплойта нет | In Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sensitive information (password reset tokens) by reading a Referredmine · redmine · CWE-532 | Высокая7,5 | — | 2,4 % | 17 окт. 2017 г. |
31Наблюдать | CVE-2013-4663Эксплойта нет | git_http_controller.rb in the redmine_git_hosting plugin for Redmine allows remote attackers to execute arbitrary commands via shell metacharedmine · redmine git hosting plugin · CWE-77 | Высокая7,5 | — | 1,9 % | 27 дек. 2014 г. |
31Наблюдать | CVE-2021-31863Эксплойта нет | Insufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows Rredmine · redmine · CWE-20 | Высокая7,5 | — | 1,7 % | 28 апр. 2021 г. |
30Наблюдать | CVE-2015-8474Эксплойта нет | Open redirect vulnerability in the valid_back_url function in app/controllers/application_controller.rb in Redmine before 2.6.7, 3.0.x beforredmine · redmine | Высокая7,4 | — | 1,8 % | 12 апр. 2016 г. |
30Наблюдать | CVE-2017-15576Эксплойта нет | Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensiredmine · redmine · CWE-200 | Высокая7,5 | — | 1,6 % | 17 окт. 2017 г. |
30Наблюдать | CVE-2017-15577Эксплойта нет | Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows remote attackers to obtain sensitive informredmine · redmine · CWE-200 | Высокая7,5 | — | 1,6 % | 17 окт. 2017 г. |
30Наблюдать | CVE-2021-30163Эксплойта нет | Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the names of private projects if issue-journal details exist that hredmine · redmine | Высокая7,5 | — | 1,2 % | 6 апр. 2021 г. |
30Наблюдать | CVE-2021-37156Эксплойта нет | Redmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling two-factor authentication for the user's account, but the intredmine · redmine · CWE-613 | Высокая7,5 | — | 1,0 % | 5 авг. 2021 г. |
30Наблюдать | CVE-2022-44030Эксплойта нет | Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks.redmine · redmine · CWE-755 | Высокая7,5 | — | 0,7 % | 6 дек. 2022 г. |
29Наблюдать | CVE-2017-15575Эксплойта нет | In Redmine before 3.2.6 and 3.3.x before 3.3.3, Redmine.pm lacks a check for whether the Repository module is enabled in a project's settingredmine · redmine | Высокая7,3 | — | 1,3 % | 17 окт. 2017 г. |
27Наблюдать | CVE-2019-18890Proof of concept | A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crredmine · redmine · CWE-89 | Средняя6,5 | — | 4,3 % | 21 нояб. 2019 г. |
27Наблюдать | CVE-2009-4079Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in Redmine 0.8.5 and earlier allows remote attackers to hijack the authentication of users fredmine · redmine · CWE-352 | Средняя6,8 | — | 0,7 % | 25 нояб. 2009 г. |
24Наблюдать | CVE-2014-1985Эксплойта нет | Open redirect vulnerability in the redirect_back_or_default function in app/controllers/application_controller.rb in Redmine before 2.4.5 anredmine · redmine · CWE-20 | Средняя5,8 | — | 2,7 % | 11 апр. 2014 г. |
24Наблюдать | CVE-2019-17427Proof of concept | In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.redmine · redmine · CWE-79 | Средняя6,1 | — | 1,6 % | 9 окт. 2019 г. |
24Наблюдать | CVE-2015-8477Эксплойта нет | Cross-site scripting (XSS) vulnerability in Redmine before 2.6.2 allows remote attackers to inject arbitrary web script or HTML via vectors redmine · redmine · CWE-79 | Средняя6,1 | — | 1,5 % | 23 мая 2017 г. |
24Наблюдать | CVE-2017-15573Эксплойта нет | In Redmine before 3.2.6 and 3.3.x before 3.3.3, XSS exists because markup is mishandled in wiki content.redmine · redmine · CWE-79 | Средняя6,1 | — | 1,3 % | 17 окт. 2017 г. |
24Наблюдать | CVE-2017-15571Эксплойта нет | In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/issues/_list.html.erb via crafted column data.redmine · redmine · CWE-79 | Средняя6,1 | — | 1,2 % | 17 окт. 2017 г. |
24Наблюдать | CVE-2017-15570Эксплойта нет | In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/timelog/_list.html.erb via crafted column data.redmine · redmine · CWE-79 | Средняя6,1 | — | 1,2 % | 17 окт. 2017 г. |
24Наблюдать | CVE-2017-15574Эксплойта нет | In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using an SVG document as an attachment.redmine · redmine · CWE-79 | Средняя6,1 | — | 1,1 % | 17 окт. 2017 г. |
24Наблюдать | CVE-2017-15568Эксплойта нет | In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/application_helper.rb via a multi-value fieldredmine · redmine · CWE-79 | Средняя6,1 | — | 1,1 % | 17 окт. 2017 г. |
24Наблюдать | CVE-2017-15569Эксплойта нет | In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/queries_helper.rb via a multi-value field witredmine · redmine · CWE-79 | Средняя6,1 | — | 0,9 % | 17 окт. 2017 г. |
24Наблюдать | CVE-2021-29274Эксплойта нет | Redmine 4.1.x before 4.1.2 allows XSS because an issue's subject is mishandled in the auto complete tip.redmine · redmine · CWE-79 | Средняя6,1 | — | 0,8 % | 29 мар. 2021 г. |
- CVE-2011-492944В плане
Unspecified vulnerability in the bazaar repository adapter in Redmine 0.9.x and 1.0.x before 1.0.5 allows remote attackers to execute arbitr
ВысокаяCVSS 7,5Готовый эксплойтEPSS 46 %redmine · redmine8 окт. 2012 г.
- CVE-2021-3016439Наблюдать
Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_issue_notes permission requirement by leveraging the Issues A
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %redmine · redmine6 апр. 2021 г.
- CVE-2017-1802636Наблюдать
Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg progra
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %redmine · redmine10 янв. 2018 г.
- CVE-2017-1557231Наблюдать
In Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sensitive information (password reset tokens) by reading a Refer
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %redmine · redmine17 окт. 2017 г.
- CVE-2013-466331Наблюдать
git_http_controller.rb in the redmine_git_hosting plugin for Redmine allows remote attackers to execute arbitrary commands via shell metacha
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %redmine · redmine git hosting plugin27 дек. 2014 г.
- CVE-2021-3186331Наблюдать
Insufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows R
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %redmine · redmine28 апр. 2021 г.
- CVE-2015-847430Наблюдать
Open redirect vulnerability in the valid_back_url function in app/controllers/application_controller.rb in Redmine before 2.6.7, 3.0.x befor
ВысокаяCVSS 7,4Эксплойта нетEPSS 2 %redmine · redmine12 апр. 2016 г.
- CVE-2017-1557630Наблюдать
Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensi
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %redmine · redmine17 окт. 2017 г.
- CVE-2017-1557730Наблюдать
Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows remote attackers to obtain sensitive inform
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %redmine · redmine17 окт. 2017 г.
- CVE-2021-3016330Наблюдать
Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the names of private projects if issue-journal details exist that h
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %redmine · redmine6 апр. 2021 г.
- CVE-2021-3715630Наблюдать
Redmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling two-factor authentication for the user's account, but the int
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %redmine · redmine5 авг. 2021 г.
- CVE-2022-4403030Наблюдать
Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %redmine · redmine6 дек. 2022 г.
- CVE-2017-1557529Наблюдать
In Redmine before 3.2.6 and 3.3.x before 3.3.3, Redmine.pm lacks a check for whether the Repository module is enabled in a project's setting
ВысокаяCVSS 7,3Эксплойта нетEPSS 1 %redmine · redmine17 окт. 2017 г.
- CVE-2019-1889027Наблюдать
A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a cr
СредняяCVSS 6,5Proof of conceptEPSS 4 %redmine · redmine21 нояб. 2019 г.
- CVE-2009-407927Наблюдать
Cross-site request forgery (CSRF) vulnerability in Redmine 0.8.5 and earlier allows remote attackers to hijack the authentication of users f
СредняяCVSS 6,8Эксплойта нетEPSS 1 %redmine · redmine25 нояб. 2009 г.
- CVE-2014-198524Наблюдать
Open redirect vulnerability in the redirect_back_or_default function in app/controllers/application_controller.rb in Redmine before 2.4.5 an
СредняяCVSS 5,8Эксплойта нетEPSS 3 %redmine · redmine11 апр. 2014 г.
- CVE-2019-1742724Наблюдать
In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.
СредняяCVSS 6,1Proof of conceptEPSS 2 %redmine · redmine9 окт. 2019 г.
- CVE-2015-847724Наблюдать
Cross-site scripting (XSS) vulnerability in Redmine before 2.6.2 allows remote attackers to inject arbitrary web script or HTML via vectors
СредняяCVSS 6,1Эксплойта нетEPSS 2 %redmine · redmine23 мая 2017 г.
- CVE-2017-1557324Наблюдать
In Redmine before 3.2.6 and 3.3.x before 3.3.3, XSS exists because markup is mishandled in wiki content.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %redmine · redmine17 окт. 2017 г.
- CVE-2017-1557124Наблюдать
In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/issues/_list.html.erb via crafted column data.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %redmine · redmine17 окт. 2017 г.
- CVE-2017-1557024Наблюдать
In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/timelog/_list.html.erb via crafted column data.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %redmine · redmine17 окт. 2017 г.
- CVE-2017-1557424Наблюдать
In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using an SVG document as an attachment.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %redmine · redmine17 окт. 2017 г.
- CVE-2017-1556824Наблюдать
In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/application_helper.rb via a multi-value field
СредняяCVSS 6,1Эксплойта нетEPSS 1 %redmine · redmine17 окт. 2017 г.
- CVE-2017-1556924Наблюдать
In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/queries_helper.rb via a multi-value field wit
СредняяCVSS 6,1Эксплойта нетEPSS 1 %redmine · redmine17 окт. 2017 г.
- CVE-2021-2927424Наблюдать
Redmine 4.1.x before 4.1.2 allows XSS because an issue's subject is mishandled in the auto complete tip.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %redmine · redmine29 мар. 2021 г.