PT-2021-4565 · Redmine · Redmine

Niubl

·

Published

2021-04-16

·

Updated

2024-03-06

·

CVE-2021-31865

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Redmine versions prior to 4.0.9 Redmine versions 4.1.x prior to 4.1.3 Redmine versions 4.2.x prior to 4.2.1
Description The issue is related to the circumvention of allowed filename extensions for uploaded attachments, potentially allowing a remote attacker to impact data integrity.
Recommendations For Redmine versions prior to 4.0.9, update to version 4.0.9 or later. For Redmine versions 4.1.x prior to 4.1.3, update to version 4.1.3 or later. For Redmine versions 4.2.x prior to 4.2.1, update to version 4.2.1 or later.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2021-05235
BIT-REDMINE-2021-31865
CVE-2021-31865
DLA-2658-1

Affected Products

Redmine