Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-8473

Опубликовано: 12 апр. 2016
Источник: debian
EPSS Низкий

Описание

The Issues API in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote authenticated users to obtain sensitive information in changeset messages by leveraging permission to read issues with related changesets from other projects.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
redminefixed3.2.0-1package
redminenot-affectedsqueezepackage
redmineend-of-lifewheezypackage

Примечания

  • https://www.redmine.org/projects/redmine/wiki/Changelog_3_0

  • https://www.redmine.org/issues/21136

  • https://www.openwall.com/lists/oss-security/2015/12/03/7

  • https://github.com/redmine/redmine/commit/8d8f612fa368a72c56b63f7ce6b7e98cab9feb22

EPSS

Процентиль: 64%
0.00465
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 10 лет назад

The Issues API in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote authenticated users to obtain sensitive information in changeset messages by leveraging permission to read issues with related changesets from other projects.

CVSS3: 4.3
nvd
почти 10 лет назад

The Issues API in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote authenticated users to obtain sensitive information in changeset messages by leveraging permission to read issues with related changesets from other projects.

CVSS3: 4.3
github
больше 3 лет назад

The Issues API in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote authenticated users to obtain sensitive information in changeset messages by leveraging permission to read issues with related changesets from other projects.

EPSS

Процентиль: 64%
0.00465
Низкий