CVE-2022-44030

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/12/2022
Last modified:
23/04/2025

Description

Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the configuration, this may require login as a registered user.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redmine:redmine:*:*:*:*:*:*:*:* 5.0.0 (including) 5.0.3 (including)