CVE-2017-15573: XSS
Published Oct 18, 2017
·Updated
In Redmine before 3.2.6 and 3.3.x before 3.3.3, XSS exists because markup is mishandled in wiki content.
Affected Software
6 affected componentsFixes available
debian/redmine
5.0.4-55.0.4-7
Redmine Redmine<=3.2.5
Redmine Redmine=3.3.0
Redmine Redmine=3.3.1
Redmine Redmine=3.3.2
Debian Debian Linux=9.0
Remediation
Event History
Oct 18, 2017
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-15573?
CVE-2017-15573 has been classified as a medium severity vulnerability due to its potential for Cross-Site Scripting (XSS) attacks.
2
How do I fix CVE-2017-15573?
To fix CVE-2017-15573, upgrade Redmine to version 3.2.6 or later, or to version 3.3.3 or later.
3
Which versions of Redmine are affected by CVE-2017-15573?
CVE-2017-15573 affects all Redmine versions prior to 3.2.6 and 3.3.x before 3.3.3.
4
What type of vulnerability is CVE-2017-15573?
CVE-2017-15573 is a Cross-Site Scripting (XSS) vulnerability caused by mishandled markup in wiki content.
5
Are there any workarounds for CVE-2017-15573?
There are no official workarounds for CVE-2017-15573; updating to a secure version is the recommended action.