This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Redmine First view 2008-10-07
Product Redmine Last view 2023-11-05
Version Type
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:a:redmine:redmine:0.5.1:*:*:*:*:*:*:* 46
cpe:2.3:a:redmine:redmine:0.6.2:*:*:*:*:*:*:* 46
cpe:2.3:a:redmine:redmine:0.5.0:*:*:*:*:*:*:* 46
cpe:2.3:a:redmine:redmine:0.4.0:*:*:*:*:*:*:* 46
cpe:2.3:a:redmine:redmine:0.2.1:*:*:*:*:*:*:* 46
cpe:2.3:a:redmine:redmine:0.4.2:*:*:*:*:*:*:* 46
cpe:2.3:a:redmine:redmine:0.2.2:*:*:*:*:*:*:* 46
cpe:2.3:a:redmine:redmine:0.7.1:*:*:*:*:*:*:* 46
cpe:2.3:a:redmine:redmine:0.6.1:*:*:*:*:*:*:* 46
cpe:2.3:a:redmine:redmine:0.6.4:*:*:*:*:*:*:* 46
cpe:2.3:a:redmine:redmine:0.6.0:*:*:*:*:*:*:* 46
cpe:2.3:a:redmine:redmine:0.1.0:*:*:*:*:*:*:* 46
cpe:2.3:a:redmine:redmine:0.7.0:-:*:*:*:*:*:* 46
cpe:2.3:a:redmine:redmine:0.7.2:*:*:*:*:*:*:* 46
cpe:2.3:a:redmine:redmine:0.6.3:*:*:*:*:*:*:* 46
cpe:2.3:a:redmine:redmine:0.4.1:*:*:*:*:*:*:* 46
cpe:2.3:a:redmine:redmine:0.3.0:*:*:*:*:*:*:* 46
cpe:2.3:a:redmine:redmine:0.7.0:rc1:*:*:*:*:*:* 46
cpe:2.3:a:redmine:redmine:*:*:*:*:*:*:*:* 45
cpe:2.3:a:redmine:redmine:0.8.1:*:*:*:*:*:*:* 45
cpe:2.3:a:redmine:redmine:0.8.0:rc1:*:*:*:*:*:* 45
cpe:2.3:a:redmine:redmine:0.8.5:*:*:*:*:*:*:* 45
cpe:2.3:a:redmine:redmine:0.7.4:*:*:*:*:*:*:* 45
cpe:2.3:a:redmine:redmine:0.8.3:*:*:*:*:*:*:* 45
cpe:2.3:a:redmine:redmine:1.0.4:*:*:*:*:*:*:* 45
cpe:2.3:a:redmine:redmine:1.0.1:*:*:*:*:*:*:* 45
cpe:2.3:a:redmine:redmine:1.0.2:*:*:*:*:*:*:* 45
cpe:2.3:a:redmine:redmine:1.0.3:*:*:*:*:*:*:* 45
cpe:2.3:a:redmine:redmine:0.8.0:-:*:*:*:*:*:* 45
cpe:2.3:a:redmine:redmine:0.8.2:*:*:*:*:*:*:* 45
cpe:2.3:a:redmine:redmine:0.8.4:*:*:*:*:*:*:* 45
cpe:2.3:a:redmine:redmine:0.7.3:*:*:*:*:*:*:* 45
cpe:2.3:a:redmine:redmine:1.0.0:*:*:*:*:*:*:* 44
cpe:2.3:a:redmine:redmine:0.9.0:*:*:*:*:*:*:* 43
cpe:2.3:a:redmine:redmine:0.9.1:*:*:*:*:*:*:* 43
cpe:2.3:a:redmine:redmine:0.9.2:*:*:*:*:*:*:* 43
cpe:2.3:a:redmine:redmine:0.9.4:*:*:*:*:*:*:* 43
cpe:2.3:a:redmine:redmine:0.9.3:*:*:*:*:*:*:* 43
cpe:2.3:a:redmine:redmine:0.9.6:*:*:*:*:*:*:* 43
cpe:2.3:a:redmine:redmine:0.9.5:*:*:*:*:*:*:* 43
cpe:2.3:a:redmine:redmine:0.8.6:*:*:*:*:*:*:* 43
cpe:2.3:a:redmine:redmine:0.8.7:*:*:*:*:*:*:* 43
cpe:2.3:a:redmine:redmine:1.1.0:*:*:*:*:*:*:* 42
cpe:2.3:a:redmine:redmine:1.1.1:*:*:*:*:*:*:* 42
cpe:2.3:a:redmine:redmine:1.0.5:*:*:*:*:*:*:* 42
cpe:2.3:a:redmine:redmine:1.1.3:*:*:*:*:*:*:* 41
cpe:2.3:a:redmine:redmine:1.2.3:*:*:*:*:*:*:* 41
cpe:2.3:a:redmine:redmine:1.3.1:*:*:*:*:*:*:* 41
cpe:2.3:a:redmine:redmine:1.1.2:*:*:*:*:*:*:* 41
cpe:2.3:a:redmine:redmine:1.2.0:*:*:*:*:*:*:* 41

Related : CVE

This CPE Product have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
  Date Alert Description
6.1 2023-11-05 CVE-2023-47260

Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS via thumbnails.

6.1 2023-11-05 CVE-2023-47259

Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in the Textile formatter.

6.1 2023-11-05 CVE-2023-47258

Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in a Markdown formatter.

6.1 2022-12-12 CVE-2022-44637

Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization in Redcloth3 Textile-formatted fields. Depending on the configuration, this may require login as a registered user.

6.1 2022-12-12 CVE-2022-44031

Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization of the blockquote syntax in Textile-formatted fields.

7.5 2022-12-06 CVE-2022-44030

Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the configuration, this may require login as a registered user.

5.3 2021-10-12 CVE-2021-42326

Redmine before 4.1.5 and 4.2.x before 4.2.3 may disclose the names of users on activity views due to an insufficient access filter.

7.5 2021-08-05 CVE-2021-37156

Redmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling two-factor authentication for the user's account, but the intended behavior is for those sessions to be terminated.

5.3 2021-04-28 CVE-2021-31866

Redmine before 4.0.9 and 4.1.x before 4.1.3 allows an attacker to learn the values of internal authentication keys by observing timing differences in string comparison operations within SysController and MailHandlerController.

5.3 2021-04-28 CVE-2021-31865

Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows users to circumvent the allowed filename extensions of uploaded attachments.

5.3 2021-04-28 CVE-2021-31864

Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows attackers to bypass the add_issue_notes permission requirement by leveraging the incoming mail handler.

7.5 2021-04-28 CVE-2021-31863

Insufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows Redmine users to read arbitrary local files accessible by the application server process.

9.8 2021-04-06 CVE-2021-30164

Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_issue_notes permission requirement by leveraging the Issues API.

7.5 2021-04-06 CVE-2021-30163

Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the names of private projects if issue-journal details exist that have changes to project_id values.

5.3 2021-04-06 CVE-2020-36308

Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performing a CSV export and reading time entries.

6.1 2021-04-06 CVE-2020-36307

Redmine before 4.0.7 and 4.1.x before 4.1.1 has stored XSS via textile inline links.

6.1 2021-04-06 CVE-2020-36306

Redmine before 4.0.7 and 4.1.x before 4.1.1 has XSS via the back_url field.

5.3 2021-04-06 CVE-2019-25026

Redmine before 3.4.13 and 4.x before 4.0.6 mishandles markup data during Textile formatting.

6.1 2021-03-29 CVE-2021-29274

Redmine 4.1.x before 4.1.2 allows XSS because an issue's subject is mishandled in the auto complete tip.

6.5 2019-11-21 CVE-2019-18890

A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crafted object query.

6.1 2019-10-09 CVE-2019-17427

In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.

8.8 2018-01-10 CVE-2017-18026

Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary commands (through the Mercurial adapter) via vectors involving a branch whose name begins with a --config= or --debugger= substring, a related issue to CVE-2017-17536.

4.3 2017-11-13 CVE-2017-16804

In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function in app/models/mailer.rb does not check whether an issue is visible, which allows remote authenticated users to obtain sensitive information by reading e-mail reminder messages.

7.5 2017-10-17 CVE-2017-15577

Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows remote attackers to obtain sensitive information.

7.5 2017-10-17 CVE-2017-15576

Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensitive information.

CWE : Common Weakness Enumeration

%idName
58% (23) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')
12% (5) CWE-200 Information Exposure
5% (2) CWE-20 Improper Input Validation
2% (1) CWE-755 Improper Handling of Exceptional Conditions
2% (1) CWE-613 Insufficient Session Expiration
2% (1) CWE-532 Information Leak Through Log Files
2% (1) CWE-352 Cross-Site Request Forgery (CSRF)
2% (1) CWE-255 Credentials Management
2% (1) CWE-203 Information Exposure Through Discrepancy
2% (1) CWE-199 Information Management Errors
2% (1) CWE-89 Improper Sanitization of Special Elements used in an SQL Command ('...
2% (1) CWE-74 Failure to Sanitize Data into a Different Plane ('Injection')

Open Source Vulnerability Database (OSVDB)

id Description
71564 Redmine app/views/layouts/base.rhtml URI XSS
70092 Redmine Unspecified Information Disclosure
70091 Redmine Textile Formatter Unspecified XSS
70090 Redmine Bazaar Repository Adapter rev Parameter Arbitrary Command Injection
61509 Redmine New Issue title Parameter XSS
60313 Redmine Ticket Deletion CSRF
60312 Redmine Unspecified XSS
48949 Redmine Unspecified XSS

OpenVAS Exploits

id Description
2011-08-03 Name : Debian Security Advisory DSA 2261-1 (redmine)
File : nvt/deb_2261_1.nasl

Snort® IPS/IDS

Date Description
2014-01-10 Redmine SCM rev parameter command injection attempt
RuleID : 26320 - Type : SERVER-WEBAPP - Revision : 5

Nessus® Vulnerability Scanner

id Description
2018-05-04 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-4191.nasl - Type: ACT_GATHER_INFO
2016-03-24 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-3529.nasl - Type: ACT_GATHER_INFO
2015-12-10 Name: The remote FreeBSD host is missing a security-related update.
File: freebsd_pkg_0e0385d19ed511e58f5c002590263bf5.nasl - Type: ACT_GATHER_INFO
2015-12-10 Name: The remote FreeBSD host is missing one or more security-related updates.
File: freebsd_pkg_21bc4d719ed811e58f5c002590263bf5.nasl - Type: ACT_GATHER_INFO
2015-12-10 Name: The remote FreeBSD host is missing one or more security-related updates.
File: freebsd_pkg_3ec2e0bc9ed711e58f5c002590263bf5.nasl - Type: ACT_GATHER_INFO
2015-12-10 Name: The remote FreeBSD host is missing a security-related update.
File: freebsd_pkg_939a70869ed611e58f5c002590263bf5.nasl - Type: ACT_GATHER_INFO
2015-12-10 Name: The remote FreeBSD host is missing one or more security-related updates.
File: freebsd_pkg_be63533c9ed711e58f5c002590263bf5.nasl - Type: ACT_GATHER_INFO
2015-12-10 Name: The remote FreeBSD host is missing one or more security-related updates.
File: freebsd_pkg_c2efcd469ed511e58f5c002590263bf5.nasl - Type: ACT_GATHER_INFO
2015-11-30 Name: The remote Debian host is missing a security update.
File: debian_DLA-351.nasl - Type: ACT_GATHER_INFO