Command Execution Vulnerability in Redmine by Redmine
CVE-2017-18026

8.8HIGH

Key Information:

Vendor

Redmine

Status
Vendor
CVE Published:
10 January 2018

What is CVE-2017-18026?

An oversight in Redmine's handling of command-line flags allows remote attackers to execute arbitrary commands through the Mercurial hg program. This vulnerability manifests when an attacker constructs a branch name that begins with the unsafe substrings '--config=' or '--debugger='. Such malformed input bypasses security checks, enabling the execution of commands with harmful implications. The flaw affects multiple versions of Redmine prior to their respective patches in 3.2.9, 3.3.6, and 3.4.4, and it is related to a previous security issue identified in CVE-2017-17536.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.