NA

CVE-2022-44030

Published: 06/12/2022 Updated: 08/12/2022
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Redmine 5.x prior to 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the configuration, this may require login as a registered user.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redmine redmine

Vendor Advisories

Debian Bug report logs - #1026048 redmine: CVE-2022-44030 CVE-2022-44637 CVE-2022-44031 Package: src:redmine; Maintainer for src:redmine is Debian Ruby Team <pkg-ruby-extras-maintainers@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Tue, 13 Dec 2022 19:06:01 UTC Severity: grave Tags: ...