Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-44030


Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the configuration, this may require login as a registered user.


Published

2022-12-06T23:15:10.407

Last Modified

2025-04-23T17:16:21.413

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    CWE-755
  • Type: Secondary
    CWE-755

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application redmine redmine ≤ 5.0.3 Yes

References