PT-2022-6948 · Redmine+1 · Redmine+1

Published

2022-12-12

·

Updated

2024-03-06

·

CVE-2022-44637

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Redmine versions 4.2.9 and earlier, 5.0.x versions prior to 5.0.4
Description The issue is related to improper sanitization in Redcloth3 Textile-formatted fields, allowing persistent XSS attacks. Depending on the configuration, exploitation may require login as a registered user. This can be exploited by a remote attacker to conduct a cross-site scripting (XSS) attack.
Recommendations For versions prior to 4.2.9 and 5.0.4, update to version 4.2.9 or 5.0.4 or later to resolve the issue. As a temporary workaround, consider disabling the Textile formatter until a patch is available. Restrict access to Redcloth3 Textile-formatted fields to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-05705
BIT-REDMINE-2022-44637
CVE-2022-44637

Affected Products

Redcloth3
Redmine