CVE-2022-44030

HIGH

Redmine 5.0.0-5.0.3 - Unauthorized File Attachment Download

Title source: llm
STIX 2.1

Description

Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the configuration, this may require login as a registered user.

References (2)

Core 2
Core References
Release Notes, Vendor Advisory
https://www.redmine.org/news/139

Scores

CVSS v3 7.5
EPSS 0.0064
EPSS Percentile 45.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-755
Status published
Products (1)
redmine/redmine 5.0.0 - 5.0.3
Published Dec 06, 2022
Tracked Since Feb 18, 2026