Redmine kayıtları
redmine üreticisine ait 51 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %2
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %90,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')23
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-20 Improper Input Validation2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-532 Insertion of Sensitive Information into Log File1
- CWE-613 Insufficient Session Expiration1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
51 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
44Planlayın | CVE-2011-4929Silahlaştırılmış | Unspecified vulnerability in the bazaar repository adapter in Redmine 0.9.x and 1.0.x before 1.0.5 allows remote attackers to execute arbitrredmine · redmine | Yüksek7,5 | — | %46,4 | 8 Eki 2012 |
39İzleyin | CVE-2021-30164İstismar yok | Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_issue_notes permission requirement by leveraging the Issues Aredmine · redmine | Kritik9,8 | — | %1,3 | 6 Nis 2021 |
36İzleyin | CVE-2017-18026İstismar yok | Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg prograredmine · redmine | Yüksek8,8 | — | %2,8 | 10 Oca 2018 |
31İzleyin | CVE-2017-15572İstismar yok | In Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sensitive information (password reset tokens) by reading a Referredmine · redmine · CWE-532 | Yüksek7,5 | — | %2,4 | 17 Eki 2017 |
31İzleyin | CVE-2013-4663İstismar yok | git_http_controller.rb in the redmine_git_hosting plugin for Redmine allows remote attackers to execute arbitrary commands via shell metacharedmine · redmine git hosting plugin · CWE-77 | Yüksek7,5 | — | %1,9 | 27 Ara 2014 |
31İzleyin | CVE-2021-31863İstismar yok | Insufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows Rredmine · redmine · CWE-20 | Yüksek7,5 | — | %1,7 | 28 Nis 2021 |
30İzleyin | CVE-2015-8474İstismar yok | Open redirect vulnerability in the valid_back_url function in app/controllers/application_controller.rb in Redmine before 2.6.7, 3.0.x beforredmine · redmine | Yüksek7,4 | — | %1,8 | 12 Nis 2016 |
30İzleyin | CVE-2017-15576İstismar yok | Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensiredmine · redmine · CWE-200 | Yüksek7,5 | — | %1,6 | 17 Eki 2017 |
30İzleyin | CVE-2017-15577İstismar yok | Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows remote attackers to obtain sensitive informredmine · redmine · CWE-200 | Yüksek7,5 | — | %1,6 | 17 Eki 2017 |
30İzleyin | CVE-2021-30163İstismar yok | Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the names of private projects if issue-journal details exist that hredmine · redmine | Yüksek7,5 | — | %1,2 | 6 Nis 2021 |
30İzleyin | CVE-2021-37156İstismar yok | Redmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling two-factor authentication for the user's account, but the intredmine · redmine · CWE-613 | Yüksek7,5 | — | %1,0 | 5 Ağu 2021 |
30İzleyin | CVE-2022-44030İstismar yok | Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks.redmine · redmine · CWE-755 | Yüksek7,5 | — | %0,7 | 6 Ara 2022 |
29İzleyin | CVE-2017-15575İstismar yok | In Redmine before 3.2.6 and 3.3.x before 3.3.3, Redmine.pm lacks a check for whether the Repository module is enabled in a project's settingredmine · redmine | Yüksek7,3 | — | %1,3 | 17 Eki 2017 |
27İzleyin | CVE-2019-18890Kavram kanıtı | A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crredmine · redmine · CWE-89 | Orta6,5 | — | %4,3 | 21 Kas 2019 |
27İzleyin | CVE-2009-4079İstismar yok | Cross-site request forgery (CSRF) vulnerability in Redmine 0.8.5 and earlier allows remote attackers to hijack the authentication of users fredmine · redmine · CWE-352 | Orta6,8 | — | %0,7 | 25 Kas 2009 |
24İzleyin | CVE-2014-1985İstismar yok | Open redirect vulnerability in the redirect_back_or_default function in app/controllers/application_controller.rb in Redmine before 2.4.5 anredmine · redmine · CWE-20 | Orta5,8 | — | %2,7 | 11 Nis 2014 |
24İzleyin | CVE-2019-17427Kavram kanıtı | In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.redmine · redmine · CWE-79 | Orta6,1 | — | %1,6 | 9 Eki 2019 |
24İzleyin | CVE-2015-8477İstismar yok | Cross-site scripting (XSS) vulnerability in Redmine before 2.6.2 allows remote attackers to inject arbitrary web script or HTML via vectors redmine · redmine · CWE-79 | Orta6,1 | — | %1,5 | 23 May 2017 |
24İzleyin | CVE-2017-15573İstismar yok | In Redmine before 3.2.6 and 3.3.x before 3.3.3, XSS exists because markup is mishandled in wiki content.redmine · redmine · CWE-79 | Orta6,1 | — | %1,3 | 17 Eki 2017 |
24İzleyin | CVE-2017-15571İstismar yok | In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/issues/_list.html.erb via crafted column data.redmine · redmine · CWE-79 | Orta6,1 | — | %1,2 | 17 Eki 2017 |
24İzleyin | CVE-2017-15570İstismar yok | In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/timelog/_list.html.erb via crafted column data.redmine · redmine · CWE-79 | Orta6,1 | — | %1,2 | 17 Eki 2017 |
24İzleyin | CVE-2017-15574İstismar yok | In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using an SVG document as an attachment.redmine · redmine · CWE-79 | Orta6,1 | — | %1,1 | 17 Eki 2017 |
24İzleyin | CVE-2017-15568İstismar yok | In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/application_helper.rb via a multi-value fieldredmine · redmine · CWE-79 | Orta6,1 | — | %1,1 | 17 Eki 2017 |
24İzleyin | CVE-2017-15569İstismar yok | In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/queries_helper.rb via a multi-value field witredmine · redmine · CWE-79 | Orta6,1 | — | %0,9 | 17 Eki 2017 |
24İzleyin | CVE-2021-29274İstismar yok | Redmine 4.1.x before 4.1.2 allows XSS because an issue's subject is mishandled in the auto complete tip.redmine · redmine · CWE-79 | Orta6,1 | — | %0,8 | 29 Mar 2021 |
- CVE-2011-492944Planlayın
Unspecified vulnerability in the bazaar repository adapter in Redmine 0.9.x and 1.0.x before 1.0.5 allows remote attackers to execute arbitr
YüksekCVSS 7,5SilahlaştırılmışEPSS %46redmine · redmine8 Eki 2012
- CVE-2021-3016439İzleyin
Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_issue_notes permission requirement by leveraging the Issues A
KritikCVSS 9,8İstismar yokEPSS %1redmine · redmine6 Nis 2021
- CVE-2017-1802636İzleyin
Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg progra
YüksekCVSS 8,8İstismar yokEPSS %3redmine · redmine10 Oca 2018
- CVE-2017-1557231İzleyin
In Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sensitive information (password reset tokens) by reading a Refer
YüksekCVSS 7,5İstismar yokEPSS %2redmine · redmine17 Eki 2017
- CVE-2013-466331İzleyin
git_http_controller.rb in the redmine_git_hosting plugin for Redmine allows remote attackers to execute arbitrary commands via shell metacha
YüksekCVSS 7,5İstismar yokEPSS %2redmine · redmine git hosting plugin27 Ara 2014
- CVE-2021-3186331İzleyin
Insufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows R
YüksekCVSS 7,5İstismar yokEPSS %2redmine · redmine28 Nis 2021
- CVE-2015-847430İzleyin
Open redirect vulnerability in the valid_back_url function in app/controllers/application_controller.rb in Redmine before 2.6.7, 3.0.x befor
YüksekCVSS 7,4İstismar yokEPSS %2redmine · redmine12 Nis 2016
- CVE-2017-1557630İzleyin
Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensi
YüksekCVSS 7,5İstismar yokEPSS %2redmine · redmine17 Eki 2017
- CVE-2017-1557730İzleyin
Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows remote attackers to obtain sensitive inform
YüksekCVSS 7,5İstismar yokEPSS %2redmine · redmine17 Eki 2017
- CVE-2021-3016330İzleyin
Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the names of private projects if issue-journal details exist that h
YüksekCVSS 7,5İstismar yokEPSS %1redmine · redmine6 Nis 2021
- CVE-2021-3715630İzleyin
Redmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling two-factor authentication for the user's account, but the int
YüksekCVSS 7,5İstismar yokEPSS %1redmine · redmine5 Ağu 2021
- CVE-2022-4403030İzleyin
Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks.
YüksekCVSS 7,5İstismar yokEPSS %1redmine · redmine6 Ara 2022
- CVE-2017-1557529İzleyin
In Redmine before 3.2.6 and 3.3.x before 3.3.3, Redmine.pm lacks a check for whether the Repository module is enabled in a project's setting
YüksekCVSS 7,3İstismar yokEPSS %1redmine · redmine17 Eki 2017
- CVE-2019-1889027İzleyin
A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a cr
OrtaCVSS 6,5Kavram kanıtıEPSS %4redmine · redmine21 Kas 2019
- CVE-2009-407927İzleyin
Cross-site request forgery (CSRF) vulnerability in Redmine 0.8.5 and earlier allows remote attackers to hijack the authentication of users f
OrtaCVSS 6,8İstismar yokEPSS %1redmine · redmine25 Kas 2009
- CVE-2014-198524İzleyin
Open redirect vulnerability in the redirect_back_or_default function in app/controllers/application_controller.rb in Redmine before 2.4.5 an
OrtaCVSS 5,8İstismar yokEPSS %3redmine · redmine11 Nis 2014
- CVE-2019-1742724İzleyin
In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.
OrtaCVSS 6,1Kavram kanıtıEPSS %2redmine · redmine9 Eki 2019
- CVE-2015-847724İzleyin
Cross-site scripting (XSS) vulnerability in Redmine before 2.6.2 allows remote attackers to inject arbitrary web script or HTML via vectors
OrtaCVSS 6,1İstismar yokEPSS %2redmine · redmine23 May 2017
- CVE-2017-1557324İzleyin
In Redmine before 3.2.6 and 3.3.x before 3.3.3, XSS exists because markup is mishandled in wiki content.
OrtaCVSS 6,1İstismar yokEPSS %1redmine · redmine17 Eki 2017
- CVE-2017-1557124İzleyin
In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/issues/_list.html.erb via crafted column data.
OrtaCVSS 6,1İstismar yokEPSS %1redmine · redmine17 Eki 2017
- CVE-2017-1557024İzleyin
In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/timelog/_list.html.erb via crafted column data.
OrtaCVSS 6,1İstismar yokEPSS %1redmine · redmine17 Eki 2017
- CVE-2017-1557424İzleyin
In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using an SVG document as an attachment.
OrtaCVSS 6,1İstismar yokEPSS %1redmine · redmine17 Eki 2017
- CVE-2017-1556824İzleyin
In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/application_helper.rb via a multi-value field
OrtaCVSS 6,1İstismar yokEPSS %1redmine · redmine17 Eki 2017
- CVE-2017-1556924İzleyin
In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/queries_helper.rb via a multi-value field wit
OrtaCVSS 6,1İstismar yokEPSS %1redmine · redmine17 Eki 2017
- CVE-2021-2927424İzleyin
Redmine 4.1.x before 4.1.2 allows XSS because an issue's subject is mishandled in the auto complete tip.
OrtaCVSS 6,1İstismar yokEPSS %1redmine · redmine29 Mar 2021