CVE-2017-16804: Infoleak
Published Nov 13, 2017
·Updated
In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function in app/models/mailer.rb does not check whether an issue is visible, which allows remote authenticated users to obtain sensitive information by reading e-mail reminder messages.
Affected Software
7 affected componentsFixes available
debian/redmine
5.0.4-55.0.4-7
Redmine Redmine<3.2.7
Redmine Redmine=3.3.0
Redmine Redmine=3.3.1
Redmine Redmine=3.3.2
Redmine Redmine=3.3.3
Debian Debian Linux=9.0
Remediation
Event History
Nov 13, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-16804?
The severity of CVE-2017-16804 is medium.
2
How does CVE-2017-16804 affect Redmine?
CVE-2017-16804 affects Redmine versions before 3.2.7 and 3.3.x before 3.3.4.
3
How can remote authenticated users exploit CVE-2017-16804?
Remote authenticated users can exploit CVE-2017-16804 by reading e-mail reminder messages to obtain sensitive information.
4
Is there a fix for CVE-2017-16804?
Yes, the fix for CVE-2017-16804 is available in Redmine version 3.2.7 and 3.3.4.
5
Where can I find more information about CVE-2017-16804?
You can find more information about CVE-2017-16804 at the following references: [1] [2] [3].