PT-2019-4747 · Redmine+1 · Redmine+1
Hoger Just
·
Published
2019-11-19
·
Updated
2019-11-26
·
CVE-2019-18890
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Redmine versions 3.2.9 and prior, 3.3.x through 3.3.9
Description
A SQL injection issue allows users to access protected information via a crafted object query. The vulnerability is related to the lack of protection measures for the SQL query structure, which can be exploited by a remote attacker to gain unauthorized access to protected information.
Recommendations
For Redmine versions 3.2.9 and prior, update to version 3.3.10 or later.
For Redmine versions 3.3.x through 3.3.9, update to version 3.3.10 or later.
As a temporary workaround, consider restricting access to sensitive data and queries until a patch is applied.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Redmine
Ubuntu