← Vulnerability feed

Vulnerability record · CVE-2022-44030 · published 6 December 2022

CVE-2022-44030: Redmine vulnerability

Redmine · Redmine

Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the configuration, this may require login as a registered user.

7.5 CVSS 3.1 High EPSS 0.66% · top 50.4% CWE-755 · CWE-755
7.5CVSS 3.1 base score
0.66%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the configuration, this may require login as a registered user.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-44030 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-30164Redmine vulnerabilityRedmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_issue_notes permission requirement by leveraging the Issues API.EPSS 1.3%8.8CVE-2017-18026Redmine vulnerabilityRedmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which …EPSS 2.8%7.5CVE-2021-37156Redmine insufficient session expiration vulnerabilityRedmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling two-factor authentication for the user's account, but the intended beh…EPSS 1.0%7.5CVE-2021-31863Redmine improper input validation vulnerabilityInsufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows Redmine us…EPSS 1.7%7.5CVE-2021-30163Redmine vulnerabilityRedmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the names of private projects if issue-journal details exist that have chang…EPSS 1.2%7.5CVE-2017-15572Redmine sensitive information in log file vulnerabilityIn Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sensitive information (password reset tokens) by reading a Referer log, b…EPSS 2.4%7.5CVE-2017-15576Redmine information exposure vulnerabilityRedmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensitive info…EPSS 1.6%7.5CVE-2017-15577Redmine information exposure vulnerabilityRedmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows remote attackers to obtain sensitive information.EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2022-44030), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.