CVE Vulnerabilities

CVE-2022-44030

Improper Handling of Exceptional Conditions

Published: Dec 06, 2022 | Modified: Apr 23, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the configuration, this may require login as a registered user.

Weakness

The product does not handle or incorrectly handles an exceptional condition.

Affected Software

NameVendorStart VersionEnd Version
RedmineRedmine5.0.0 (including)5.0.3 (including)
RedmineUbuntubionic*
RedmineUbuntufocal*
RedmineUbuntukinetic*
RedmineUbuntulunar*
RedmineUbuntumantic*
RedmineUbuntutrusty*
RedmineUbuntuxenial*

References