CVE-2022-44637: XSS
Published Dec 12, 2022
·Updated
Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization in Redcloth3 Textile-formatted fields. Depending on the configuration, this may require login as a registered user.
Affected Software
2 affected components
Redmine Redmine<4.2.9
Redmine Redmine>=5.0.0<5.0.4
Event History
Dec 12, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-44637?
CVE-2022-44637 is a vulnerability in Redmine versions before 4.2.9 and 5.0.x before 5.0.4 that allows persistent XSS in its Textile formatter.
2
How does CVE-2022-44637 affect Redmine?
CVE-2022-44637 affects Redmine versions before 4.2.9 and 5.0.x before 5.0.4.
3
What is the severity of CVE-2022-44637?
CVE-2022-44637 has a severity rating of 6.1 (medium).
4
How can I fix CVE-2022-44637?
To fix CVE-2022-44637, you should upgrade Redmine to version 4.2.9 or 5.0.4, depending on your current version.
5
Where can I find more information about CVE-2022-44637?
More information about CVE-2022-44637 can be found at this link: [https://www.redmine.org/projects/redmine/wiki/Security_Advisories]