ZeroHour

CVE-2022-44030

CVSS 3.1
7.5 high
EPSS
<1%p49
Published
()
Modified
Description

Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the configuration, this may require login as a registered user.

Vendors
redmine
Products
redmine
Weakness
CWE-755
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.