Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the configuration, this may require login as a registered user.
The product does not handle or incorrectly handles an exceptional condition.
Link | Tags |
---|---|
https://www.redmine.org/projects/redmine/wiki/Security_Advisories | patch vendor advisory |
https://www.redmine.org/news/139 | release notes vendor advisory |