The Issues API in Redmine before 2.6.8, 3.0.x before 3.0.6,...
Vulnerability Description
The Issues API in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote authenticated users to obtain sensitive information in changeset messages by leveraging permission to read issues with related changesets from other projects.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-8473
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/bid/78621
- https://www.redmine.org/projects/redmine/wiki/Changelog_3_0
- https://www.redmine.org/issues/21136
- https://www.redmine.org/versions/105
- https://www.redmine.org/projects/redmine/wiki/Changelog_3_1
- http://www.debian.org/security/2016/dsa-3529
- https://github.com/redmine/redmine/commit/8d8f612fa368a72c56b63f7ce6b7e98cab9feb22
More from debian
View All →Affected Vendor
debian
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.