VDB

CVE-2014-1985

CVE-2014-1985 PUBLISHED CVSS 5.800000190734863 MEDIUM

Open redirect vulnerability in the redirect_back_or_default function in app/controllers/application_controller.rb in Redmine before 2.4.5 and 2.5.x before 2.5.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the back url (back_url parameter).

EPSS 1.82% · 83.2th percentile

Risk Scores

CVSS 2.0
5.800000190734863
EPSS Score
1.82%
83.2th percentile

Affected Products

VendorProductVersions
redmineredmine2.4.2, 0, 2.4.1
n/an/an/a

Timeline

  • Apr 11, 2014 CVE Published
  • Feb 4, 2022 EPSS Score
  • May 17, 2022 CVE Updated
  • Mar 7, 2023 EPSS Score
  • Mar 17, 2025 EPSS Score
  • Mar 21, 2025 EPSS Score
  • Apr 1, 2025 EPSS Score
  • Apr 2, 2025 EPSS Score
  • Apr 13, 2025 EPSS Score
  • Apr 14, 2025 EPSS Score
  • Apr 16, 2025 EPSS Score
  • Apr 19, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›