CVE-2022-44030

HIGH

Redmine <5.0.4 - Info Disclosure

Title source: llm
STIX 2.1

Description

Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the configuration, this may require login as a registered user.

Scores

CVSS v3 7.5
EPSS 0.0035
EPSS Percentile 57.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-755
Status published
Products (1)
redmine/redmine 5.0.0 - 5.0.3
Published Dec 06, 2022
Tracked Since Feb 18, 2026