CVE-2017-15576: Infoleak
Published Oct 18, 2017
·Updated
Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensitive information.
Affected Software
6 affected componentsFixes available
debian/redmine
5.0.4-55.0.4-7
Redmine Redmine<=3.2.5
Redmine Redmine=3.3.0
Redmine Redmine=3.3.1
Redmine Redmine=3.3.2
Debian Debian Linux=9.0
Remediation
Event History
Oct 18, 2017
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-15576?
CVE-2017-15576 is classified as a medium severity vulnerability due to its potential for exposing sensitive information.
2
How do I fix CVE-2017-15576?
To fix CVE-2017-15576, upgrade Redmine to version 3.2.6 or later, or 3.3.3 or later.
3
Which versions of Redmine are affected by CVE-2017-15576?
CVE-2017-15576 affects Redmine versions prior to 3.2.6 and 3.3.x prior to 3.3.3.
4
What type of vulnerability is CVE-2017-15576?
CVE-2017-15576 is an information disclosure vulnerability that allows remote attackers to access sensitive data.
5
Is Debian Linux affected by CVE-2017-15576?
Yes, Debian Linux versions 9.0 running vulnerable Redmine packages are affected by CVE-2017-15576.