In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.Referenceshttps://www.redmine.org/projects/redmine/wiki/Security_Advisorieshttps://www.debian.org/security/2019/dsa-4574https://seclists.org/bugtraq/2019/Nov/31https://usn.ubuntu.com/4200-1/https://github.com/RealLinkers/CVE-2019-17427