CVE-2012-2054

Redmine before 1.3.2 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set attributes in the (1) Comment, (2) Document, (3) IssueCategory, (4) MembersController, (5) Message, (6) News, (7) TimeEntry, (8) Version, (9) Wiki, (10) UserPreference, or (11) Board model via a modified URL, related to a "mass assignment" vulnerability, a different vulnerability than CVE-2012-0327.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 50%
VendorProductVersion
redmineredmine
𝑥
≤ 1.3.1
redmineredmine
0.1.0
redmineredmine
0.2.1
redmineredmine
0.2.2
redmineredmine
0.3.0
redmineredmine
0.4.0
redmineredmine
0.4.1
redmineredmine
0.4.2
redmineredmine
0.5.0
redmineredmine
0.5.1
redmineredmine
0.6.0
redmineredmine
0.6.1
redmineredmine
0.6.2
redmineredmine
0.6.3
redmineredmine
0.6.4
redmineredmine
0.7.0
redmineredmine
0.7.0:rc1
redmineredmine
0.7.1
redmineredmine
0.7.2
redmineredmine
0.7.3
redmineredmine
0.7.4
redmineredmine
0.8.0
redmineredmine
0.8.0:rc1
redmineredmine
0.8.1
redmineredmine
0.8.2
redmineredmine
0.8.3
redmineredmine
0.8.4
redmineredmine
0.8.5
redmineredmine
0.8.6
redmineredmine
0.8.7
redmineredmine
0.9.0
redmineredmine
0.9.1
redmineredmine
0.9.2
redmineredmine
0.9.3
redmineredmine
0.9.4
redmineredmine
0.9.5
redmineredmine
0.9.6
redmineredmine
1.0.0
redmineredmine
1.0.1
redmineredmine
1.0.2
redmineredmine
1.0.3
redmineredmine
1.0.4
redmineredmine
1.0.5
redmineredmine
1.1.0
redmineredmine
1.1.1
redmineredmine
1.1.2
redmineredmine
1.1.3
redmineredmine
1.2.0
redmineredmine
1.2.1
redmineredmine
1.2.2
redmineredmine
1.2.3
redmineredmine
1.3.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
redmine
bookworm
5.0.4-5+deb12u1
fixed
bookworm (security)
5.0.4-5+deb12u1
fixed
sid
5.0.4-7
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
redmine
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
not-affected
oneiric
ignored
natty
ignored
maverick
ignored
lucid
ignored
hardy
dne
Common Weakness Enumeration