VYPR

Redmine

by Redmine

Source repositories

CVEs (56)

  • CVE-2011-4929Oct 8, 2012
    risk 0.07cvss epss 0.46

    Unspecified vulnerability in the bazaar repository adapter in Redmine 0.9.x and 1.0.x before 1.0.5 allows remote attackers to execute arbitrary commands via unknown vectors.

  • CVE-2024-37664Jun 17, 2024
    risk 0.00cvss epss 0.00

    Redmi router RB03 v1.0.57 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or hijack the traffic between the victim and any remote server by sending out forged TCP RST messages to evict NAT mappings in the router.

  • CVE-2024-37663Jun 17, 2024
    risk 0.00cvss epss 0.00

    Redmi router RB03 v1.0.57 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the victim can hijack the traffic between the victim and any remote server by sending out forged ICMP redirect messages.

  • CVE-2023-47259Nov 5, 2023
    risk 0.00cvss epss 0.00

    Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in the Textile formatter.

  • CVE-2023-47260Nov 5, 2023
    risk 0.00cvss epss 0.00

    Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS via thumbnails.

  • CVE-2023-47258Nov 5, 2023
    risk 0.00cvss epss 0.00

    Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in a Markdown formatter.

  • CVE-2022-44637Dec 12, 2022
    risk 0.00cvss epss 0.00

    Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization in Redcloth3 Textile-formatted fields. Depending on the configuration, this may require login as a registered user.

  • CVE-2022-44031Dec 12, 2022
    risk 0.00cvss epss 0.00

    Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization of the blockquote syntax in Textile-formatted fields.

  • CVE-2022-44030Dec 6, 2022
    risk 0.00cvss epss 0.01

    Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the configuration, this may require login as a registered user.

  • CVE-2021-42326Oct 12, 2021
    risk 0.00cvss epss 0.01

    Redmine before 4.1.5 and 4.2.x before 4.2.3 may disclose the names of users on activity views due to an insufficient access filter.

  • CVE-2021-37156Aug 5, 2021
    risk 0.00cvss epss 0.01

    Redmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling two-factor authentication for the user's account, but the intended behavior is for those sessions to be terminated.

  • CVE-2021-31863Apr 28, 2021
    risk 0.00cvss epss 0.02

    Insufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows Redmine users to read arbitrary local files accessible by the application server process.

  • CVE-2021-31864Apr 28, 2021
    risk 0.00cvss epss 0.01

    Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows attackers to bypass the add_issue_notes permission requirement by leveraging the incoming mail handler.

  • CVE-2021-31865Apr 28, 2021
    risk 0.00cvss epss 0.01

    Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows users to circumvent the allowed filename extensions of uploaded attachments.

  • CVE-2021-31866Apr 28, 2021
    risk 0.00cvss epss 0.01

    Redmine before 4.0.9 and 4.1.x before 4.1.3 allows an attacker to learn the values of internal authentication keys by observing timing differences in string comparison operations within SysController and MailHandlerController.

  • CVE-2021-30163Apr 6, 2021
    risk 0.00cvss epss 0.01

    Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the names of private projects if issue-journal details exist that have changes to project_id values.

  • CVE-2020-36306Apr 6, 2021
    risk 0.00cvss epss 0.01

    Redmine before 4.0.7 and 4.1.x before 4.1.1 has XSS via the back_url field.

  • CVE-2020-36307Apr 6, 2021
    risk 0.00cvss epss 0.01

    Redmine before 4.0.7 and 4.1.x before 4.1.1 has stored XSS via textile inline links.

  • CVE-2020-36308Apr 6, 2021
    risk 0.00cvss epss 0.01

    Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performing a CSV export and reading time entries.

  • CVE-2019-25026Apr 6, 2021
    risk 0.00cvss epss 0.01

    Redmine before 3.4.13 and 4.x before 4.0.6 mishandles markup data during Textile formatting.