CVE-2017-15572

Severity CVSS v4.0:
Pending analysis
Type:
CWE-532 Information Exposure Through Log Files
Publication date:
18/10/2017
Last modified:
20/04/2025

Description

In Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sensitive information (password reset tokens) by reading a Referer log, because account/lost_password does not use a redirect.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redmine:redmine:*:*:*:*:*:*:*:* 3.2.5 (including)
cpe:2.3:a:redmine:redmine:3.3.0:*:*:*:*:*:*:*
cpe:2.3:a:redmine:redmine:3.3.1:*:*:*:*:*:*:*
cpe:2.3:a:redmine:redmine:3.3.2:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*