PT-2020-6943 · Redmine · Redmine

Published

2020-08-12

·

Updated

2024-03-06

·

CVE-2021-30164

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Redmine versions prior to 4.0.8 Redmine versions 4.1.x prior to 4.1.2
Description The issue is related to permission handling errors in the Redmine project and task management web application. Exploitation of this issue allows a remote attacker to access confidential data, compromise its integrity, and cause a denial of service. The vulnerability can be exploited by leveraging the Issues API to bypass the add issue notes permission requirement.
Recommendations For Redmine versions prior to 4.0.8, update to version 4.0.8 or later. For Redmine versions 4.1.x prior to 4.1.2, update to version 4.1.2 or later. As a temporary workaround, consider restricting access to the Issues API until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-07825
BIT-REDMINE-2021-30164
CVE-2021-30164
DLA-2658-1

Affected Products

Redmine