PT-2019-4747 · Redmine+1 · Redmine+1

Hoger Just

·

Published

2019-11-19

·

Updated

2019-11-26

·

CVE-2019-18890

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Redmine versions 3.2.9 and prior, 3.3.x through 3.3.9
Description A SQL injection issue allows users to access protected information via a crafted object query. The vulnerability is related to the lack of protection measures for the SQL query structure, which can be exploited by a remote attacker to gain unauthorized access to protected information.
Recommendations For Redmine versions 3.2.9 and prior, update to version 3.3.10 or later. For Redmine versions 3.3.x through 3.3.9, update to version 3.3.10 or later. As a temporary workaround, consider restricting access to sensitive data and queries until a patch is applied.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-01319
CVE-2019-18890
DSA-4574-1
USN-4200-1

Affected Products

Redmine
Ubuntu