Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <7c4034ea-f116-808e-bcb3-749cd3e35e34@gmx.ch>
Date: Thu, 19 Nov 2020 14:51:06 +0000
From: sjw@....ch
To: oss-security@...ts.openwall.com
Subject: Unpatched XSS in Redmine 4.1

Hi

This is a heads up about a public, unpatched XSS vulnerability in
Redmine 4.1.

About 3 months ago, a public issue [1] has been reported in the Redmine
bug tracker regarding unsanitized HTML tags. This basically means that
you can inject any HTML code in issue titles, including JavaScript.
I've successfully verified this on Redmine 4.1. There's a (untested)
patch attached in the issue.

I've also sent this to the Redmine security team but since there was no
response from the maintainers so far and the issue is already public for
a long time I'm posting this here to make people aware of it.

Best regards


[1] https://redmine.org/issues/33846



Download attachment "signature.asc" of type "application/pgp-signature" (834 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.