Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-8346

Опубликовано: 12 апр. 2016
Источник: debian

Описание

app/views/timelog/_form.html.erb in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote attackers to obtain sensitive information about subjects of issues by viewing the time logging form.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
redminefixed3.2.0-1package
redmineend-of-lifewheezypackage
redmineend-of-lifesqueezepackage

Примечания

  • https://www.redmine.org/projects/redmine/wiki/Changelog_3_0

  • https://www.redmine.org/projects/redmine/wiki/Security_Advisories

  • https://www.redmine.org/issues/21150 (private)

  • https://www.openwall.com/lists/oss-security/2015/11/25/1

  • Commit: https://github.com/redmine/redmine/commit/945a091c94a9ed651f61e225fa8646479478e9d4

  • Commit: https://github.com/redmine/redmine/commit/c096dde88ff02872ba35edc4dc403c80a7867b5c

  • For squeeze, the bug is in app/views/timelog/edit.rhtml

  • upstream fixed in 2.6.8, 3.0.6 and 3.1.2

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 10 лет назад

app/views/timelog/_form.html.erb in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote attackers to obtain sensitive information about subjects of issues by viewing the time logging form.

CVSS3: 5.3
nvd
почти 10 лет назад

app/views/timelog/_form.html.erb in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote attackers to obtain sensitive information about subjects of issues by viewing the time logging form.

CVSS3: 5.3
github
больше 3 лет назад

app/views/timelog/_form.html.erb in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote attackers to obtain sensitive information about subjects of issues by viewing the time logging form.