Redmine 0.6.3

CPE Details

Redmine 0.6.3
0.6.3
2008-10-08 13:18 +00:00
2011-04-29 13:35 +00:00

Alerte pour un CPE

Stay informed of any changes for a specific CPE.
Alert management

CPE Name: cpe:2.3:a:redmine:redmine:0.6.3:*:*:*:*:*:*:*

Informations

Vendor

redmine

Product

redmine

Version

0.6.3

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-47258 2023-11-04 23:00 +00:00 Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in a Markdown formatter.
6.1
MEDIUM
CVE-2023-47259 2023-11-04 23:00 +00:00 Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in the Textile formatter.
6.1
MEDIUM
CVE-2023-47260 2023-11-04 23:00 +00:00 Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS via thumbnails.
6.1
MEDIUM
CVE-2022-44031 2022-12-11 23:00 +00:00 Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization of the blockquote syntax in Textile-formatted fields.
6.1
MEDIUM
CVE-2022-44637 2022-12-11 23:00 +00:00 Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization in Redcloth3 Textile-formatted fields. Depending on the configuration, this may require login as a registered user.
6.1
MEDIUM
CVE-2012-2054 2022-10-03 14:15 +00:00 Redmine before 1.3.2 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set attributes in the (1) Comment, (2) Document, (3) IssueCategory, (4) MembersController, (5) Message, (6) News, (7) TimeEntry, (8) Version, (9) Wiki, (10) UserPreference, or (11) Board model via a modified URL, related to a "mass assignment" vulnerability, a different vulnerability than CVE-2012-0327.
5
CVE-2011-4928 2022-10-03 14:15 +00:00 Cross-site scripting (XSS) vulnerability in the textile formatter in Redmine before 1.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
4.3
CVE-2021-42326 2021-10-12 16:08 +00:00 Redmine before 4.1.5 and 4.2.x before 4.2.3 may disclose the names of users on activity views due to an insufficient access filter.
5.3
MEDIUM
CVE-2021-31863 2021-04-28 04:17 +00:00 Insufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows Redmine users to read arbitrary local files accessible by the application server process.
7.5
HIGH
CVE-2021-31864 2021-04-28 04:16 +00:00 Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows attackers to bypass the add_issue_notes permission requirement by leveraging the incoming mail handler.
5.3
MEDIUM
CVE-2021-31865 2021-04-28 04:16 +00:00 Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows users to circumvent the allowed filename extensions of uploaded attachments.
5.3
MEDIUM
CVE-2021-31866 2021-04-28 04:16 +00:00 Redmine before 4.0.9 and 4.1.x before 4.1.3 allows an attacker to learn the values of internal authentication keys by observing timing differences in string comparison operations within SysController and MailHandlerController.
5.3
MEDIUM
CVE-2021-30163 2021-04-06 05:59 +00:00 Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the names of private projects if issue-journal details exist that have changes to project_id values.
7.5
HIGH
CVE-2020-36306 2021-04-06 05:59 +00:00 Redmine before 4.0.7 and 4.1.x before 4.1.1 has XSS via the back_url field.
6.1
MEDIUM
CVE-2020-36307 2021-04-06 05:59 +00:00 Redmine before 4.0.7 and 4.1.x before 4.1.1 has stored XSS via textile inline links.
6.1
MEDIUM
CVE-2020-36308 2021-04-06 05:59 +00:00 Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performing a CSV export and reading time entries.
5.3
MEDIUM
CVE-2019-25026 2021-04-06 05:59 +00:00 Redmine before 3.4.13 and 4.x before 4.0.6 mishandles markup data during Textile formatting.
5.3
MEDIUM
CVE-2021-30164 2021-04-06 05:58 +00:00 Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_issue_notes permission requirement by leveraging the Issues API.
9.8
CRITICAL
CVE-2019-18890 2019-11-21 16:46 +00:00 A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crafted object query.
6.5
MEDIUM
CVE-2019-17427 2019-10-09 22:42 +00:00 In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.
6.1
MEDIUM
CVE-2017-18026 2018-01-10 08:00 +00:00 Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary commands (through the Mercurial adapter) via vectors involving a branch whose name begins with a --config= or --debugger= substring, a related issue to CVE-2017-17536.
8.8
HIGH
CVE-2017-16804 2017-11-13 19:00 +00:00 In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function in app/models/mailer.rb does not check whether an issue is visible, which allows remote authenticated users to obtain sensitive information by reading e-mail reminder messages.
4.3
MEDIUM
CVE-2016-10515 2017-10-18 00:00 +00:00 In Redmine before 3.2.3, there are stored XSS vulnerabilities affecting Textile and Markdown text formatting, and project homepages.
6.1
MEDIUM
CVE-2017-15568 2017-10-18 00:00 +00:00 In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/application_helper.rb via a multi-value field with a crafted value that is mishandled during rendering of issue history.
6.1
MEDIUM
CVE-2017-15569 2017-10-18 00:00 +00:00 In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/queries_helper.rb via a multi-value field with a crafted value that is mishandled during rendering of an issue list.
6.1
MEDIUM
CVE-2017-15570 2017-10-18 00:00 +00:00 In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/timelog/_list.html.erb via crafted column data.
6.1
MEDIUM
CVE-2017-15571 2017-10-18 00:00 +00:00 In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/issues/_list.html.erb via crafted column data.
6.1
MEDIUM
CVE-2017-15572 2017-10-18 00:00 +00:00 In Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sensitive information (password reset tokens) by reading a Referer log, because account/lost_password does not use a redirect.
7.5
HIGH
CVE-2017-15573 2017-10-18 00:00 +00:00 In Redmine before 3.2.6 and 3.3.x before 3.3.3, XSS exists because markup is mishandled in wiki content.
6.1
MEDIUM
CVE-2017-15574 2017-10-18 00:00 +00:00 In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using an SVG document as an attachment.
6.1
MEDIUM
CVE-2017-15575 2017-10-18 00:00 +00:00 In Redmine before 3.2.6 and 3.3.x before 3.3.3, Redmine.pm lacks a check for whether the Repository module is enabled in a project's settings, which might allow remote attackers to obtain sensitive differences information or possibly have unspecified other impact.
7.3
HIGH
CVE-2017-15576 2017-10-18 00:00 +00:00 Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensitive information.
7.5
HIGH
CVE-2017-15577 2017-10-18 00:00 +00:00 Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows remote attackers to obtain sensitive information.
7.5
HIGH
CVE-2015-8477 2017-05-23 01:56 +00:00 Cross-site scripting (XSS) vulnerability in Redmine before 2.6.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving flash message rendering.
6.1
MEDIUM
CVE-2015-8346 2016-04-12 12:00 +00:00 app/views/timelog/_form.html.erb in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote attackers to obtain sensitive information about subjects of issues by viewing the time logging form.
5.3
MEDIUM
CVE-2015-8473 2016-04-12 12:00 +00:00 The Issues API in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote authenticated users to obtain sensitive information in changeset messages by leveraging permission to read issues with related changesets from other projects.
4.3
MEDIUM
CVE-2015-8474 2016-04-12 12:00 +00:00 Open redirect vulnerability in the valid_back_url function in app/controllers/application_controller.rb in Redmine before 2.6.7, 3.0.x before 3.0.5, and 3.1.x before 3.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted back_url parameter, as demonstrated by "@attacker.com," a different vulnerability than CVE-2014-1985.
7.4
HIGH
CVE-2015-8537 2016-04-12 12:00 +00:00 app/views/journals/index.builder in Redmine before 2.6.9, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote attackers to obtain sensitive information by viewing an Atom feed.
5.3
MEDIUM
CVE-2014-1985 2014-04-11 12:00 +00:00 Open redirect vulnerability in the redirect_back_or_default function in app/controllers/application_controller.rb in Redmine before 2.4.5 and 2.5.x before 2.5.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the back url (back_url parameter).
5.8
CVE-2012-0327 2012-04-04 08:00 +00:00 Cross-site scripting (XSS) vulnerability in Redmine before 1.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
4.3
CVE-2009-4459 2009-12-30 18:00 +00:00 Redmine 0.8.7 and earlier uses the title tag before defining the character encoding in a meta tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks and inject arbitrary script via UTF-7 encoded values in the title parameter to a new issue page, which may be interpreted as script by Internet Explorer 7 and 8.
4.3
CVE-2009-4078 2009-11-25 20:22 +00:00 Multiple cross-site scripting (XSS) vulnerabilities in Redmine 0.8.5 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
4.3
CVE-2009-4079 2009-11-25 20:22 +00:00 Cross-site request forgery (CSRF) vulnerability in Redmine 0.8.5 and earlier allows remote attackers to hijack the authentication of users for requests that delete a ticket via unspecified vectors.
6.8
CVE-2008-4481 2008-10-07 23:00 +00:00 Cross-site scripting (XSS) vulnerability in Redmine 0.7.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
4.3
Click on the button to the left (OFF), to authorize the inscription of cookie improving the functionalities of the site. Click on the button to the left (Accept all), to unauthorize the inscription of cookie improving the functionalities of the site.