Candidate: CVE-2019-17427 PublicDate: 2019-10-10 02:05:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17427 https://www.redmine.org/projects/redmine/wiki/Security_Advisories https://ubuntu.com/security/notices/USN-4200-1 Description: In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N [6.1 MEDIUM] Patches_redmine: upstream_redmine: released (4.0.4-1) precise/esm_redmine: DNE trusty_redmine: ignored (out of standard support) trusty/esm_redmine: DNE xenial_redmine: released (3.2.1-2ubuntu0.2) bionic_redmine: released (3.4.4-1ubuntu0.1) disco_redmine: released (4.0.1-2ubuntu0.1) eoan_redmine: not-affected (4.0.4-1) devel_redmine: not-affected (4.0.4-1)