CVE-2022-44031: XSS
Published Dec 12, 2022
·Updated
Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization of the blockquote syntax in Textile-formatted fields.
Affected Software
2 affected components
Redmine Redmine<4.2.9
Redmine Redmine>=5.0.0<5.0.4
Event History
Dec 12, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this Redmine vulnerability?
The vulnerability ID for this Redmine vulnerability is CVE-2022-44031.
2
What is the severity of CVE-2022-44031?
The severity of CVE-2022-44031 is medium.
3
Which versions of Redmine are affected by CVE-2022-44031?
Redmine versions before 4.2.9 and 5.0.x before 5.0.4 are affected by CVE-2022-44031.
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is 79.
5
How can I fix the CVE-2022-44031 vulnerability?
To fix the CVE-2022-44031 vulnerability, it is recommended to update Redmine to version 4.2.9 or 5.0.4 or later.