CVE-2022-44030

HIGH

Redmine <5.0.4 - Info Disclosure

Title source: llm

Description

Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the configuration, this may require login as a registered user.

Scores

CVSS v3 7.5
EPSS 0.0035
EPSS Percentile 57.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-755
Status published

Affected Products (1)

redmine/redmine < 5.0.3

Timeline

Published Dec 06, 2022
Tracked Since Feb 18, 2026