Vulnerabilities (CVE)

Filtered by vendor Redmine Subscribe
Filtered by product Redmine
Total 50 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-30164 2 Debian, Redmine 2 Debian Linux, Redmine 2024-11-21 7.5 HIGH 9.8 CRITICAL
Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_issue_notes permission requirement by leveraging the Issues API.
CVE-2021-30163 2 Debian, Redmine 2 Debian Linux, Redmine 2024-11-21 5.0 MEDIUM 7.5 HIGH
Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the names of private projects if issue-journal details exist that have changes to project_id values.
CVE-2021-29274 1 Redmine 1 Redmine 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Redmine 4.1.x before 4.1.2 allows XSS because an issue's subject is mishandled in the auto complete tip.
CVE-2020-36308 2 Debian, Redmine 2 Debian Linux, Redmine 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performing a CSV export and reading time entries.
CVE-2020-36307 2 Debian, Redmine 2 Debian Linux, Redmine 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Redmine before 4.0.7 and 4.1.x before 4.1.1 has stored XSS via textile inline links.
CVE-2020-36306 2 Debian, Redmine 2 Debian Linux, Redmine 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Redmine before 4.0.7 and 4.1.x before 4.1.1 has XSS via the back_url field.
CVE-2019-25026 2 Debian, Redmine 2 Debian Linux, Redmine 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
Redmine before 3.4.13 and 4.x before 4.0.6 mishandles markup data during Textile formatting.
CVE-2019-18890 2 Debian, Redmine 2 Debian Linux, Redmine 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crafted object query.
CVE-2019-17427 1 Redmine 1 Redmine 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.
CVE-2017-18026 2 Debian, Redmine 2 Debian Linux, Redmine 2024-11-21 6.8 MEDIUM 8.8 HIGH
Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary commands (through the Mercurial adapter) via vectors involving a branch whose name begins with a --config= or --debugger= substring, a related issue to CVE-2017-17536.