İçeriğe atla
Noroxi

Redmine kayıtları

redmine üreticisine ait 51 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
1 · %2
Pre-auth RCE
3
Düzeltme kaydı olan
%90,2
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

51 kayıt
  • CVE-2011-4929
    44Planlayın

    Unspecified vulnerability in the bazaar repository adapter in Redmine 0.9.x and 1.0.x before 1.0.5 allows remote attackers to execute arbitr

    YüksekCVSS 7,5SilahlaştırılmışEPSS %46

    redmine · redmine8 Eki 2012

  • CVE-2021-30164
    39İzleyin

    Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_issue_notes permission requirement by leveraging the Issues A

    KritikCVSS 9,8İstismar yokEPSS %1

    redmine · redmine6 Nis 2021

  • CVE-2017-18026
    36İzleyin

    Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg progra

    YüksekCVSS 8,8İstismar yokEPSS %3

    redmine · redmine10 Oca 2018

  • CVE-2017-15572
    31İzleyin

    In Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sensitive information (password reset tokens) by reading a Refer

    YüksekCVSS 7,5İstismar yokEPSS %2

    redmine · redmine17 Eki 2017

  • CVE-2013-4663
    31İzleyin

    git_http_controller.rb in the redmine_git_hosting plugin for Redmine allows remote attackers to execute arbitrary commands via shell metacha

    YüksekCVSS 7,5İstismar yokEPSS %2

    redmine · redmine git hosting plugin27 Ara 2014

  • CVE-2021-31863
    31İzleyin

    Insufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows R

    YüksekCVSS 7,5İstismar yokEPSS %2

    redmine · redmine28 Nis 2021

  • CVE-2015-8474
    30İzleyin

    Open redirect vulnerability in the valid_back_url function in app/controllers/application_controller.rb in Redmine before 2.6.7, 3.0.x befor

    YüksekCVSS 7,4İstismar yokEPSS %2

    redmine · redmine12 Nis 2016

  • CVE-2017-15576
    30İzleyin

    Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensi

    YüksekCVSS 7,5İstismar yokEPSS %2

    redmine · redmine17 Eki 2017

  • CVE-2017-15577
    30İzleyin

    Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows remote attackers to obtain sensitive inform

    YüksekCVSS 7,5İstismar yokEPSS %2

    redmine · redmine17 Eki 2017

  • CVE-2021-30163
    30İzleyin

    Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the names of private projects if issue-journal details exist that h

    YüksekCVSS 7,5İstismar yokEPSS %1

    redmine · redmine6 Nis 2021

  • CVE-2021-37156
    30İzleyin

    Redmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling two-factor authentication for the user's account, but the int

    YüksekCVSS 7,5İstismar yokEPSS %1

    redmine · redmine5 Ağu 2021

  • CVE-2022-44030
    30İzleyin

    Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks.

    YüksekCVSS 7,5İstismar yokEPSS %1

    redmine · redmine6 Ara 2022

  • CVE-2017-15575
    29İzleyin

    In Redmine before 3.2.6 and 3.3.x before 3.3.3, Redmine.pm lacks a check for whether the Repository module is enabled in a project's setting

    YüksekCVSS 7,3İstismar yokEPSS %1

    redmine · redmine17 Eki 2017

  • CVE-2019-18890
    27İzleyin

    A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a cr

    OrtaCVSS 6,5Kavram kanıtıEPSS %4

    redmine · redmine21 Kas 2019

  • CVE-2009-4079
    27İzleyin

    Cross-site request forgery (CSRF) vulnerability in Redmine 0.8.5 and earlier allows remote attackers to hijack the authentication of users f

    OrtaCVSS 6,8İstismar yokEPSS %1

    redmine · redmine25 Kas 2009

  • CVE-2014-1985
    24İzleyin

    Open redirect vulnerability in the redirect_back_or_default function in app/controllers/application_controller.rb in Redmine before 2.4.5 an

    OrtaCVSS 5,8İstismar yokEPSS %3

    redmine · redmine11 Nis 2014

  • CVE-2019-17427
    24İzleyin

    In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.

    OrtaCVSS 6,1Kavram kanıtıEPSS %2

    redmine · redmine9 Eki 2019

  • CVE-2015-8477
    24İzleyin

    Cross-site scripting (XSS) vulnerability in Redmine before 2.6.2 allows remote attackers to inject arbitrary web script or HTML via vectors

    OrtaCVSS 6,1İstismar yokEPSS %2

    redmine · redmine23 May 2017

  • CVE-2017-15573
    24İzleyin

    In Redmine before 3.2.6 and 3.3.x before 3.3.3, XSS exists because markup is mishandled in wiki content.

    OrtaCVSS 6,1İstismar yokEPSS %1

    redmine · redmine17 Eki 2017

  • CVE-2017-15571
    24İzleyin

    In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/issues/_list.html.erb via crafted column data.

    OrtaCVSS 6,1İstismar yokEPSS %1

    redmine · redmine17 Eki 2017

  • CVE-2017-15570
    24İzleyin

    In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/timelog/_list.html.erb via crafted column data.

    OrtaCVSS 6,1İstismar yokEPSS %1

    redmine · redmine17 Eki 2017

  • CVE-2017-15574
    24İzleyin

    In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using an SVG document as an attachment.

    OrtaCVSS 6,1İstismar yokEPSS %1

    redmine · redmine17 Eki 2017

  • CVE-2017-15568
    24İzleyin

    In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/application_helper.rb via a multi-value field

    OrtaCVSS 6,1İstismar yokEPSS %1

    redmine · redmine17 Eki 2017

  • CVE-2017-15569
    24İzleyin

    In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/queries_helper.rb via a multi-value field wit

    OrtaCVSS 6,1İstismar yokEPSS %1

    redmine · redmine17 Eki 2017

  • CVE-2021-29274
    24İzleyin

    Redmine 4.1.x before 4.1.2 allows XSS because an issue's subject is mishandled in the auto complete tip.

    OrtaCVSS 6,1İstismar yokEPSS %1

    redmine · redmine29 Mar 2021