Bug | wheezy | jessie | stretch | sid | Description |
---|
CVE-2017-18026 | vulnerable | vulnerable | vulnerable | fixed | Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does ... |
CVE-2017-16804 | vulnerable | vulnerable | vulnerable | fixed | In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function ... |
CVE-2017-15577 | vulnerable | vulnerable | vulnerable | fixed | Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of ... |
CVE-2017-15576 | vulnerable | vulnerable | vulnerable | fixed | Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry ... |
CVE-2017-15575 | vulnerable | vulnerable | vulnerable | fixed | In Redmine before 3.2.6 and 3.3.x before 3.3.3, Redmine.pm lacks a ... |
CVE-2017-15574 | vulnerable | vulnerable | vulnerable | fixed | In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible ... |
CVE-2017-15573 | vulnerable | vulnerable | vulnerable | fixed | In Redmine before 3.2.6 and 3.3.x before 3.3.3, XSS exists because ... |
CVE-2017-15572 | vulnerable | vulnerable | vulnerable | fixed | In Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can ... |
CVE-2017-15571 | vulnerable | vulnerable | vulnerable | fixed | In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, ... |
CVE-2017-15570 | vulnerable | vulnerable | vulnerable | fixed | In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, ... |
CVE-2017-15569 | vulnerable | vulnerable | vulnerable | fixed | In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, ... |
CVE-2017-15568 | vulnerable | vulnerable | vulnerable | fixed | In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, ... |
CVE-2016-10515 | vulnerable | vulnerable | fixed | fixed | In Redmine before 3.2.3, there are stored XSS vulnerabilities affecting ... |
CVE-2015-8537 | vulnerable | fixed | fixed | fixed | app/views/journals/index.builder in Redmine before 2.6.9, 3.0.x before ... |
CVE-2015-8477 | vulnerable | fixed | fixed | fixed | Cross-site scripting (XSS) vulnerability in Redmine before 2.6.2 ... |
CVE-2015-8474 | vulnerable | fixed | fixed | fixed | Open redirect vulnerability in the valid_back_url function in ... |
CVE-2015-8473 | vulnerable | fixed | fixed | fixed | The Issues API in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x ... |
CVE-2015-8346 | vulnerable | fixed | fixed | fixed | app/views/timelog/_form.html.erb in Redmine before 2.6.8, 3.0.x before ... |
CVE-2014-1985 | vulnerable | fixed | fixed | fixed | Open redirect vulnerability in the redirect_back_or_default function ... |
Bug | Description |
---|
TEMP-0000000-838979 | Escape href attribute in auto links |
TEMP-0000000-56C871 | Fixes permission check in QueriesController |
CVE-2012-2054 | Redmine before 1.3.2 does not properly restrict the use of a hash to ... |
CVE-2012-0327 | Cross-site scripting (XSS) vulnerability in Redmine before 1.3.2 ... |
CVE-2011-4929 | Unspecified vulnerability in the bazaar repository adapter in Redmine ... |
CVE-2011-4928 | Cross-site scripting (XSS) vulnerability in the textile formatter in ... |
CVE-2011-4927 | Unspecified vulnerability in the bazaar repository adapter in Redmine ... |
CVE-2009-4459 | Redmine 0.8.7 and earlier uses the title tag before defining the ... |
CVE-2009-4079 | Cross-site request forgery (CSRF) vulnerability in Redmine 0.8.5 and ... |
CVE-2009-4078 | Multiple cross-site scripting (XSS) vulnerabilities in Redmine 0.8.5 ... |