Actions
Feature #36992
closedredmine computed custom field
Status:
Closed
Priority:
Normal
Assignee:
-
Category:
Custom fields
Target version:
-
Start date:
Due date:
% Done:
0%
Estimated time:
Resolution:
Wont fix
Description
i think this plugin must be by default in core redmine
all users need it
Related issues
Updated by Holger Just over 2 years ago
- Related to Feature #1712: add custom fields that are calculations of other fields added
Updated by Holger Just over 2 years ago
- Status changed from New to Closed
- Resolution set to Wont fix
The plugin (and its various forks) rely on administrators entering raw Ruby code which is then evaluated. This effectively results in the plugin being an unmitigated remote-code-execution vulnerability which goes against the security guarantees of Redmine.
As such, this plugin will never be part of Redmine and I would strongly recommend to not use it anywhere because of the incredible security risks it brings.
Actions