CVE-2019-18890: SQL Injection
A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crafted object query.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-18890?
CVE-2019-18890 is a SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 that allows users to access protected information via a crafted object query.
What is the severity of CVE-2019-18890?
The severity of CVE-2019-18890 is medium (CVSS score of 6.5).
How does CVE-2019-18890 affect Redmine?
CVE-2019-18890 affects Redmine versions 3.2.9 and 3.3.x before 3.3.10, allowing users to access protected information through a SQL injection vulnerability.
How do I fix the SQL injection vulnerability in Redmine (CVE-2019-18890)?
To fix the SQL injection vulnerability (CVE-2019-18890) in Redmine, you should update to version 3.4.2-1 or later.
Where can I find more information about CVE-2019-18890?
You can find more information about CVE-2019-18890 on the Debian Security Tracker and Redmine Security Advisories.