|
[Japanese]
|
JVNDB-2008-000038
|
Redmine vulnerable to cross-site scripting
|
Redmine, open source project management software, contains a cross-site scripting vulnerbility.
Redmine is open source project management software written by Ruby on Rails framework. Redmine contains a cross-site scripting vulnerability.
Toshiharu Sugiyama of UBsecure, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
|
Base Metrics:
4.0 (Medium)
[IPA Score]
- Access Vector: Network
- Access Complexity: Low
- Authentication: Single Instance
- Confidentiality Impact: None
- Integrity Impact: Partial
- Availability Impact: None
|
|
|
Redmine
- Redmine 0.7.2 and earlier
|
|
An arbitrary script can be executed on the user's web browser.
|
[Update the Software]
Apply the latest update provided by the developer.
|
Redmine
|
- Cross-site Scripting(CWE-79) [IPA Evaluation]
|
- CVE-2008-4481
|
- JVN : JVN#00945448
- National Vulnerability Database (NVD) : CVE-2008-4481
- JVN iPedia (Japanese) : JVNDB-2008-000038
|
[2008/07/08]
Web page published
|