CVE-2019-17427: XSS
Published Oct 10, 2019
·Updated
In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.
Affected Software
3 affected componentsFixes available
Redmine Redmine<3.4.11
Redmine Redmine>=4.0.0<4.0.4
debian/redmine
5.0.4-5+deb12u16.0.5+ds-16.0.6+ds-6
Event History
Oct 10, 2019
CVE Published
via MITRE·12:42 AM
Data Sourced
via MITRE·12:42 AM
Description
Data Sourced
via NVD·02:05 AM
DescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·11:23 PM
Description
Feb 21, 2026
Data Sourced
via Ubuntu·12:11 AM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·12:12 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-17427.
2
What is the severity of CVE-2019-17427?
The severity of CVE-2019-17427 is medium with a CVSS score of 6.1.
3
What software versions are affected by CVE-2019-17427?
Redmine versions before 3.4.11 and 4.0.x before 4.0.4 are affected.
4
How does the persistent XSS occur in CVE-2019-17427?
Persistent XSS occurs in CVE-2019-17427 due to textile formatting errors.
5
Are there any remediation steps available for CVE-2019-17427?
Yes, you can refer to the following references for remediation steps: [reference 1](https://github.com/RealLinkers/CVE-2019-17427), [reference 2](https://seclists.org/bugtraq/2019/Nov/31), [reference 3](https://usn.ubuntu.com/4200-1/).