First published: Tue Dec 06 2022(Updated: )
Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the configuration, this may require login as a registered user.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Redmine Redmine | >=5.0.0<=5.0.3 | |
>=5.0.0<=5.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-44030 is a vulnerability in Redmine 5.x before 5.0.4 that allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks.
CVE-2022-44030 has a severity rating of 7.5 (high).
CVE-2022-44030 allows unauthorized users to download file attachments of any Issue or any Wiki page in Redmine 5.x before 5.0.4.
To fix CVE-2022-44030, you should upgrade Redmine to version 5.0.4 or later.
You can find more information about CVE-2022-44030 in the Redmine security advisories: [https://www.redmine.org/news/139](https://www.redmine.org/news/139) and [https://www.redmine.org/projects/redmine/wiki/Security_Advisories](https://www.redmine.org/projects/redmine/wiki/Security_Advisories).