Your submission was sent successfully! Close

Thank you for contacting us. A member of our team will be in touch shortly. Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

21 – 30 of 50 results


CVE-2019-18890

Medium priority
Fixed

A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crafted object query.

1 affected packages

redmine

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
redmine Not affected Fixed
Show less packages

CVE-2019-17427

Medium priority
Fixed

In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.

1 affected packages

redmine

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
redmine Fixed Fixed
Show less packages

CVE-2017-18026

Medium priority

Some fixes available 1 of 6

Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary commands (through the Mercurial...

1 affected packages

redmine

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
redmine Not in release Not in release Not affected Not affected Vulnerable
Show less packages

CVE-2017-16804

Medium priority

Some fixes available 1 of 6

In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function in app/models/mailer.rb does not check whether an issue is visible, which allows remote authenticated users to obtain sensitive information by reading e-mail...

1 affected packages

redmine

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
redmine Not in release Not in release Not affected Not affected Vulnerable
Show less packages

CVE-2017-15577

Medium priority

Some fixes available 1 of 4

Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows remote attackers to obtain sensitive information.

1 affected packages

redmine

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
redmine Not in release Not in release Not affected Not affected Vulnerable
Show less packages

CVE-2017-15576

Low priority

Some fixes available 1 of 6

Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensitive information.

1 affected packages

redmine

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
redmine Not in release Not in release Not affected Not affected Vulnerable
Show less packages

CVE-2017-15575

Low priority

Some fixes available 1 of 6

In Redmine before 3.2.6 and 3.3.x before 3.3.3, Redmine.pm lacks a check for whether the Repository module is enabled in a project's settings, which might allow remote attackers to obtain sensitive differences information...

1 affected packages

redmine

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
redmine Not in release Not in release Not affected Not affected Vulnerable
Show less packages

CVE-2017-15574

Medium priority

Some fixes available 1 of 6

In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using an SVG document as an attachment.

1 affected packages

redmine

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
redmine Not in release Not in release Not affected Not affected Vulnerable
Show less packages

CVE-2017-15573

Medium priority

Some fixes available 1 of 6

In Redmine before 3.2.6 and 3.3.x before 3.3.3, XSS exists because markup is mishandled in wiki content.

1 affected packages

redmine

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
redmine Not in release Not in release Not affected Not affected Vulnerable
Show less packages

CVE-2017-15572

Medium priority

Some fixes available 1 of 4

In Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sensitive information (password reset tokens) by reading a Referer log, because account/lost_password does not use a redirect.

1 affected packages

redmine

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
redmine Not in release Not in release Not affected Not affected Vulnerable
Show less packages