{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-15T19:55:56.181033800Z","vulnerabilities":[{"cve":{"id":"CVE-2009-4079","sourceIdentifier":"cve@mitre.org","published":"2009-11-25T22:00:00.733","lastModified":"2025-04-09T00:30:58.490","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Cross-site request forgery (CSRF) vulnerability in Redmine 0.8.5 and earlier allows remote attackers to hijack the authentication of users for requests that delete a ticket via unspecified vectors."},{"lang":"es","value":"Vulnerabilidad de falsificación de petición en sitios cruzados en Redmine v0.8.5 y anteriores permite a atacantes remotos secuestras las autenticación de los usuarios para peticiones que borren un ticket a través de vectores inespecificos."}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-352"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:*:*:*:*:*:*:*:*","versionEndIncluding":"0.8.5","matchCriteriaId":"F7E66CDC-BDA5-4F19-81FA-621C3F42B7A4"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.1.0:*:*:*:*:*:*:*","matchCriteriaId":"DCCB74CF-B69C-4ACF-B676-17082D54A769"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.2.1:*:*:*:*:*:*:*","matchCriteriaId":"D0254A2D-10A5-4843-BE58-72A3B5284DB1"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.2.2:*:*:*:*:*:*:*","matchCriteriaId":"E19773B3-33A6-439A-93BB-1FB4FA86D4D8"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.3.0:*:*:*:*:*:*:*","matchCriteriaId":"1314065B-1B7A-41BC-89F2-EAEE8EA8A6BA"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.4.0:*:*:*:*:*:*:*","matchCriteriaId":"F0BE09F2-954D-4A3E-B2D1-981EEF6AD0CF"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.4.1:*:*:*:*:*:*:*","matchCriteriaId":"FBEA2E09-2CA8-4999-A841-02A8488F851A"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.4.2:*:*:*:*:*:*:*","matchCriteriaId":"F99DB71A-FBBE-4FFF-8EC6-D0EDAE8EDEF3"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.5.0:*:*:*:*:*:*:*","matchCriteriaId":"CF1E2430-4FFB-4AB4-A2BD-55711486D257"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.5.1:*:*:*:*:*:*:*","matchCriteriaId":"0026FFCE-D748-41F4-B4E8-9852B3ED9532"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.6.0:*:*:*:*:*:*:*","matchCriteriaId":"554098E4-A9E5-4153-B8CD-8C987B7A8527"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.6.1:*:*:*:*:*:*:*","matchCriteriaId":"117F62E1-BEC6-416F-AD68-BC1AA260CC1D"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.6.2:*:*:*:*:*:*:*","matchCriteriaId":"086659CB-5DD4-4B19-8223-76A85DF82D46"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.6.3:*:*:*:*:*:*:*","matchCriteriaId":"1850A5B4-747D-4D6F-B625-7DE4857790E8"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.6.4:*:*:*:*:*:*:*","matchCriteriaId":"5FDE853B-C003-4C9F-9A00-AF84CCD0A05F"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.7.0:*:*:*:*:*:*:*","matchCriteriaId":"E235F356-CE27-4CFC-A064-D93E3FE0C7AE"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.7.0:rc1:*:*:*:*:*:*","matchCriteriaId":"7F66B7C8-0D70-4E53-90BC-938101BEB3B4"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.7.1:*:*:*:*:*:*:*","matchCriteriaId":"D4EDE791-F1E6-4E9C-9924-9AA8A34A2D36"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.7.2:*:*:*:*:*:*:*","matchCriteriaId":"A25E4182-E8BE-45BC-A591-463963D51341"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.7.3:*:*:*:*:*:*:*","matchCriteriaId":"450BD64C-120C-4803-84D8-7A2186B148B5"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.7.4:*:*:*:*:*:*:*","matchCriteriaId":"650A5A39-D2F1-41D1-B985-7051D0035B50"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.8.0:*:*:*:*:*:*:*","matchCriteriaId":"0012C0B4-0B5A-4588-A81F-32652DECDA45"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.8.0:rc1:*:*:*:*:*:*","matchCriteriaId":"052CA2E7-73E8-4BA2-A98E-A527D635505D"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.8.1:*:*:*:*:*:*:*","matchCriteriaId":"D961E2C0-4061-4CCA-AA6A-6CB3AA096933"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.8.2:*:*:*:*:*:*:*","matchCriteriaId":"B91BB4D5-4700-4874-8473-5CF8C9A39B5D"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.8.3:*:*:*:*:*:*:*","matchCriteriaId":"69C39736-8851-4072-89C7-9635CC28BD02"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.8.4:*:*:*:*:*:*:*","matchCriteriaId":"F8C1857C-A87F-4BE1-A4D9-458310DF0F3B"}]}]}],"references":[{"url":"http://jvn.jp/en/jp/JVN87341298/index.html","source":"cve@mitre.org","tags":["Patch"]},{"url":"http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000074.html","source":"cve@mitre.org","tags":["Patch"]},{"url":"http://rubyforge.org/frs/shownotes.php?release_id=41440","source":"cve@mitre.org","tags":["Patch"]},{"url":"http://secunia.com/advisories/37420","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"http://www.redmine.org/wiki/redmine/Changelog#v087-2009-11-15","source":"cve@mitre.org","tags":["Patch"]},{"url":"http://www.securityfocus.com/bid/37066","source":"cve@mitre.org"},{"url":"http://www.vupen.com/english/advisories/2009/3291","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/54334","source":"cve@mitre.org"},{"url":"http://jvn.jp/en/jp/JVN87341298/index.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]},{"url":"http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000074.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]},{"url":"http://rubyforge.org/frs/shownotes.php?release_id=41440","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]},{"url":"http://secunia.com/advisories/37420","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"http://www.redmine.org/wiki/redmine/Changelog#v087-2009-11-15","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]},{"url":"http://www.securityfocus.com/bid/37066","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.vupen.com/english/advisories/2009/3291","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/54334","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}