CVE-2022-44030
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/12/2022
Last modified:
23/04/2025
Description
Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the configuration, this may require login as a registered user.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:redmine:redmine:*:*:*:*:*:*:*:* | 5.0.0 (including) | 5.0.3 (including) |
To consult the complete list of CPE names with products and versions, see this page



