Feature #36992

redmine computed custom field

Added by ashraf alzyoud 3 months ago. Updated 2 months ago.

Status:ClosedStart date:
Priority:NormalDue date:
Assignee:-% Done:

0%

Category:Custom fields
Target version:-
Resolution:Wont fix

Description

i think this plugin must be by default in core redmine
all users need it


Related issues

Related to Redmine - Feature #1712: add custom fields that are calculations of other fields New 2008-07-30

History

#1 Updated by Holger Just 2 months ago

  • Related to Feature #1712: add custom fields that are calculations of other fields added

#2 Updated by Holger Just 2 months ago

  • Status changed from New to Closed
  • Resolution set to Wont fix

The plugin (and its various forks) rely on administrators entering raw Ruby code which is then evaluated. This effectively results in the plugin being an unmitigated remote-code-execution vulnerability which goes against the security guarantees of Redmine.

As such, this plugin will never be part of Redmine and I would strongly recommend to not use it anywhere because of the incredible security risks it brings.

Also available in: Atom PDF