CVE-2017-15577: Infoleak
Published Oct 18, 2017
·Updated
Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows remote attackers to obtain sensitive information.
Affected Software
6 affected componentsFixes available
debian/redmine
5.0.4-55.0.4-7
Redmine Redmine<=3.2.5
Redmine Redmine=3.3.0
Redmine Redmine=3.3.1
Redmine Redmine=3.3.2
Debian Debian Linux=9.0
Remediation
Event History
Oct 18, 2017
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-15577?
CVE-2017-15577 is classified as a high-severity vulnerability due to the potential for sensitive information disclosure.
2
How do I fix CVE-2017-15577?
To mitigate CVE-2017-15577, upgrade Redmine to version 3.2.6 or 3.3.3 or later.
3
What versions of Redmine are affected by CVE-2017-15577?
Redmine versions before 3.2.6 and 3.3.x before 3.3.3 are affected by CVE-2017-15577.
4
What type of attack is possible with CVE-2017-15577?
CVE-2017-15577 allows remote attackers to gain access to sensitive information through wiki link rendering issues.
5
Is CVE-2017-15577 specific to any operating system?
CVE-2017-15577 affects Redmine applications and is not specific to any particular operating system.