[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    [oss-security] Unpatched XSS in Redmine 4.1
From:       sjw () gmx ! ch
Date:       2020-11-19 14:51:06
Message-ID: 7c4034ea-f116-808e-bcb3-749cd3e35e34 () gmx ! ch
[Download RAW message or body]

[Attachment #2 (multipart/mixed)]


Hi

This is a heads up about a public, unpatched XSS vulnerability in
Redmine 4.1.

About 3 months ago, a public issue [1] has been reported in the Redmine
bug tracker regarding unsanitized HTML tags. This basically means that
you can inject any HTML code in issue titles, including JavaScript.
I've successfully verified this on Redmine 4.1. There's a (untested)
patch attached in the issue.

I've also sent this to the Redmine security team but since there was no
response from the maintainers so far and the issue is already public for
a long time I'm posting this here to make people aware of it.

Best regards


[1] https://redmine.org/issues/33846


["signature.asc" (application/pgp-signature)]

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic