Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the configuration, this may require login as a registered user.
The product does not handle or incorrectly handles an exceptional condition.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Redmine | Redmine | 5.0.0 (including) | 5.0.3 (including) |
Redmine | Ubuntu | bionic | * |
Redmine | Ubuntu | kinetic | * |
Redmine | Ubuntu | lunar | * |
Redmine | Ubuntu | mantic | * |
Redmine | Ubuntu | trusty | * |
Redmine | Ubuntu | xenial | * |