Oval Definition:oval:com.ubuntu.xenial:def:201584740000000
Revision Date:2016-04-12Version:1
Title:CVE-2015-8474 on Ubuntu 16.04 LTS (xenial) - medium.
Description:Open redirect vulnerability in the valid_back_url function in app/controllers/application_controller.rb in Redmine before 2.6.7, 3.0.x before 3.0.5, and 3.1.x before 3.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted back_url parameter, as demonstrated by "@attacker.com," a different vulnerability than CVE-2014-1985.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2015-8474
Platform(s):Ubuntu 16.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 16.04 LTS (xenial) is installed.
  • AND redmine package in xenial, is related to the CVE in some way and has been fixed (note: '3.2.0-1').
  • BACK