CVE-2022-44030: High severity redmine vulnerability
Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the configuration, this may require login as a registered user.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-44030?
CVE-2022-44030 is a vulnerability in Redmine 5.x before 5.0.4 that allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks.
What is the severity of CVE-2022-44030?
CVE-2022-44030 has a severity rating of 7.5 (high).
How does CVE-2022-44030 impact Redmine?
CVE-2022-44030 allows unauthorized users to download file attachments of any Issue or any Wiki page in Redmine 5.x before 5.0.4.
How can I fix CVE-2022-44030?
To fix CVE-2022-44030, you should upgrade Redmine to version 5.0.4 or later.
Where can I find more information about CVE-2022-44030?
You can find more information about CVE-2022-44030 in the Redmine security advisories: [https://www.redmine.org/news/139](https://www.redmine.org/news/139) and [https://www.redmine.org/projects/redmine/wiki/Security_Advisories](https://www.redmine.org/projects/redmine/wiki/Security_Advisories).