CVE-2017-15572: High severity Redmine Redmine vulnerability
In Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sensitive information (password reset tokens) by reading a Referer log, because account/lostpassword does not use a redirect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15572?
CVE-2017-15572 is classified as a medium severity vulnerability that can lead to information disclosure.
How do I fix CVE-2017-15572?
To fix CVE-2017-15572, upgrade Redmine to version 3.2.6 or later for the 3.2.x branch or to version 3.3.3 or later for the 3.3.x branch.
What types of information are affected by CVE-2017-15572?
CVE-2017-15572 allows remote attackers to obtain sensitive information, specifically password reset tokens.
Which versions of Redmine are vulnerable to CVE-2017-15572?
Redmine versions prior to 3.2.6 and versions 3.3.0 to 3.3.2 are affected by CVE-2017-15572.
Is there a reference for CVE-2017-15572?
Security advisories and tracking for CVE-2017-15572 can be found on the official Redmine project and Debian security tracker.