PT-2021-4608 · Redmine · Redmine

Published

2021-04-06

·

Updated

2024-03-06

·

CVE-2020-36306

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Redmine versions prior to 4.0.7 Redmine versions 4.1.x prior to 4.1.1
Description The issue is related to a lack of protection for the web page structure, allowing a remote attacker to impact data integrity. The problem can be exploited via the back url field, leading to XSS.
Recommendations For Redmine versions prior to 4.0.7, update to version 4.0.7 or later. For Redmine versions 4.1.x prior to 4.1.1, update to version 4.1.1 or later. As a temporary workaround, consider restricting access to the back url field to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2021-05292
BIT-REDMINE-2020-36306
CVE-2020-36306
DLA-2658-1

Affected Products

Redmine