CVE-2015-8474: High severity debian linux vulnerability
Open redirect vulnerability in the validbackurl function in app/controllers/applicationcontroller.rb in Redmine before 2.6.7, 3.0.x before 3.0.5, and 3.1.x before 3.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted backurl parameter, as demonstrated by "@attacker.com," a different vulnerability than CVE-2014-1985.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8474?
CVE-2015-8474 is classified as a high severity vulnerability due to its potential to enable phishing attacks.
How do I fix CVE-2015-8474?
To fix CVE-2015-8474, upgrade Redmine to version 2.6.7 or later, or to 3.0.5 or later for 3.0.x, and 3.1.1 or later for 3.1.x.
Which versions of Redmine are affected by CVE-2015-8474?
CVE-2015-8474 affects Redmine versions prior to 2.6.7, all 3.0.x versions before 3.0.5, and all 3.1.x versions before 3.1.1.
Can CVE-2015-8474 be exploited remotely?
Yes, CVE-2015-8474 can be exploited remotely by attackers to redirect users to malicious sites.
What type of attacks are possible with CVE-2015-8474?
CVE-2015-8474 can be exploited to conduct phishing attacks by redirecting users to arbitrary web sites.