From 141a65dbebda8f9bf7a1f65613181725db9523f3 Mon Sep 17 00:00:00 2001 From: Jason Unovitch Date: Thu, 10 Dec 2015 01:08:28 +0000 Subject: [PATCH] Catch up on documentation of Redmine vulnerabilities PR: 205110 Security: CVE-2015-8346 Security: CVE-2015-8473 Security: CVE-2015-8474 Security: https://vuxml.FreeBSD.org/freebsd/21bc4d71-9ed8-11e5-8f5c-002590263bf5.html Security: https://vuxml.FreeBSD.org/freebsd/3ec2e0bc-9ed7-11e5-8f5c-002590263bf5.html Security: https://vuxml.FreeBSD.org/freebsd/be63533c-9ed7-11e5-8f5c-002590263bf5.html --- security/vuxml/vuln.xml | 250 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 250 insertions(+) diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index c39ebb75a85e..58fd9da1f8d8 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -58,6 +58,256 @@ Notes: --> + + redmine -- information leak vulnerability + + + redmine + 2.6.9 + 3.0.03.0.7 + 3.1.03.1.3 + + + + +

Redmine reports:

+
+

Data disclosure in atom feed.

+
+ +
+ + http://www.redmine.org/projects/redmine/wiki/Security_Advisories + + + 2015-12-05 + 2015-12-10 + +
+ + + redmine -- multiple vulnerabilities + + + redmine + 2.6.8 + 3.0.03.0.6 + 3.1.03.1.2 + + + + +

Redmine reports:

+
+

Potential changeset message disclosure in issues API.

+

Data disclosure on the time logging form

+
+ +
+ + CVE-2015-8346 + CVE-2015-8473 + http://www.redmine.org/projects/redmine/wiki/Security_Advisories + http://www.openwall.com/lists/oss-security/2015/11/25/12 + http://www.openwall.com/lists/oss-security/2015/12/03/7 + + + 2015-11-14 + 2015-12-10 + +
+ + + redmine -- open redirect vulnerability + + + redmine + 2.5.12.6.7 + 3.0.03.0.5 + 3.1.0 + + + + +

Redmine reports:

+
+

Open Redirect vulnerability.

+
+ +
+ + CVE-2015-8474 + http://www.redmine.org/projects/redmine/wiki/Security_Advisories + http://www.openwall.com/lists/oss-security/2015/12/04/1 + + + 2015-09-20 + 2015-12-10 + +
+ + + redmine -- potential XSS vulnerability + + + redmine + 2.6.2 + + + + +

Redmine reports:

+
+

Potential XSS vulnerability when rendering some flash messages.

+
+ +
+ + CVE-2015-8477 + http://www.redmine.org/projects/redmine/wiki/Security_Advisories + http://www.openwall.com/lists/oss-security/2015/12/05/6 + + + 2015-02-19 + 2015-12-10 + +
+ + + redmine -- information leak vulnerability + + + redmine + 2.4.6 + 2.5.02.5.2 + + + + +

Redmine reports:

+
+

Potential data leak (project names) in the invalid form + authenticity token error screen.

+
+ +
+ + http://www.redmine.org/projects/redmine/wiki/Security_Advisories + + + 2014-07-06 + 2015-12-10 + +
+ + + redmine -- open redirect vulnerability + + + redmine + 2.4.5 + 2.5.0 + + + + +

Redmine reports:

+
+

Open Redirect vulnerability

+
+ +
+ + CVE-2014-1985 + http://www.redmine.org/projects/redmine/wiki/Security_Advisories + https://jvn.jp/en/jp/JVN93004610/index.html + + + 2014-03-29 + 2015-12-10 + +
+ + + redmine -- XSS vulnerability + + + redmine + 2.1.02.1.2 + + + + +

Redmine reports:

+
+

XSS vulnerability

+
+ +
+ + http://www.redmine.org/projects/redmine/wiki/Security_Advisories + + + 2012-09-30 + 2015-12-10 + +
+ + + redmine -- multiple vulnerabilities + + + redmine + 1.3.2 + + + + +

Redmine reports:

+
+

Mass-assignemnt vulnerability that would allow an attacker to + bypass part of the security checks.

+

Persistent XSS vulnerability

+
+ +
+ + CVE-2012-0327 + http://www.redmine.org/projects/redmine/wiki/Security_Advisories + http://jvn.jp/en/jp/JVN93406632/ + + + 2012-03-11 + 2015-12-10 + +
+ + + redmine -- CSRF protection bypass + + + redmine + 1.3.0 + + + + +

Redmine reports:

+
+

Vulnerability that would allow an attacker to bypass the CSRF + protection.

+
+ +
+ + http://www.redmine.org/projects/redmine/wiki/Security_Advisories + + + 2011-12-10 + 2015-12-10 + +
+ jenkins -- multiple vulnerabilities