Candidate: CVE-2009-4078 PublicDate: 2009-11-25 22:00:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4078 Description: Multiple cross-site scripting (XSS) vulnerabilities in Redmine 0.8.5 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. Ubuntu-Description: Notes: sbeattie> fixed before package made it into any archive Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_redmine: upstream_redmine: released dapper_redmine: DNE hardy_redmine: DNE intrepid_redmine: DNE jaunty_redmine: DNE karmic_redmine: DNE lucid_redmine: ignored (reached end-of-life) maverick_redmine: ignored (reached end-of-life) natty_redmine: ignored (reached end-of-life) oneiric_redmine: ignored (reached end-of-life) precise_redmine: ignored (reached end-of-life) precise/esm_redmine: DNE (precise was needs-triage) quantal_redmine: ignored (reached end-of-life) raring_redmine: ignored (reached end-of-life) saucy_redmine: ignored (reached end-of-life) trusty_redmine: not-affected (0.9.0svn2902-1) trusty/esm_redmine: DNE (trusty was not-affected [0.9.0svn2902-1]) utopic_redmine: ignored (reached end-of-life) vivid_redmine: ignored (reached end-of-life) vivid/stable-phone-overlay_redmine: DNE vivid/ubuntu-core_redmine: DNE wily_redmine: ignored (reached end-of-life) xenial_redmine: not-affected (0.9.0svn2902-1) yakkety_redmine: ignored (reached end-of-life) zesty_redmine: ignored (reached end-of-life) artful_redmine: not-affected (0.9.0svn2902-1) bionic_redmine: not-affected (0.9.0svn2902-1) devel_redmine: not-affected (0.9.0svn2902-1)