CVE-2017-15575: High severity Redmine Redmine vulnerability
Published Oct 18, 2017
·Updated
In Redmine before 3.2.6 and 3.3.x before 3.3.3, Redmine.pm lacks a check for whether the Repository module is enabled in a project's settings, which might allow remote attackers to obtain sensitive differences information or possibly have unspecified other impact.
Affected Software
6 affected componentsFixes available
debian/redmine
5.0.4-55.0.4-7
Redmine Redmine<=3.2.5
Redmine Redmine=3.3.0
Redmine Redmine=3.3.1
Redmine Redmine=3.3.2
Debian Debian Linux=9.0
Remediation
Event History
Oct 18, 2017
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-15575?
The severity of CVE-2017-15575 is rated as high with a score of 7.3.
2
How do I fix CVE-2017-15575?
To fix CVE-2017-15575, update Redmine to version 3.2.6 or 3.3.3 or later.
3
Which versions of Redmine are affected by CVE-2017-15575?
CVE-2017-15575 affects Redmine versions prior to 3.2.6 and versions 3.3.0 to 3.3.2.
4
Can CVE-2017-15575 lead to data leakage?
Yes, CVE-2017-15575 may allow remote attackers to obtain sensitive difference information due to a lack of checks in Redmine.
5
Is there a specific software update needed for CVE-2017-15575?
Yes, the specific updates needed are Redmine versions 3.2.6 or 3.3.3 and later.