CVE-2014-1985: Input Validation
Published Apr 11, 2014
·Updated
Open redirect vulnerability in the redirectbackordefault function in app/controllers/applicationcontroller.rb in Redmine before 2.4.5 and 2.5.x before 2.5.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the back url (backurl parameter).
Affected Software
6 affected components
Redmine Redmine<=2.4.4
Redmine Redmine=2.4.0
Redmine Redmine=2.4.1
Redmine Redmine=2.4.2
Redmine Redmine=2.4.3
Redmine Redmine=2.5.0
Remediation
Event History
Apr 11, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:55 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-1985?
CVE-2014-1985 is considered a medium severity vulnerability due to its potential for phishing attacks.
2
How do I fix CVE-2014-1985?
To fix CVE-2014-1985, upgrade Redmine to version 2.4.5 or later, or version 2.5.1 or later.
3
What type of vulnerability is CVE-2014-1985?
CVE-2014-1985 is an open redirect vulnerability.
4
Which versions of Redmine are affected by CVE-2014-1985?
CVE-2014-1985 affects Redmine versions prior to 2.4.5 and 2.5.x before 2.5.1.
5
What can attackers do with CVE-2014-1985?
Attackers can exploit CVE-2014-1985 to redirect users to arbitrary websites, facilitating phishing attacks.