PT-2021-4569 · Redmine · Redmine

Niubl

·

Published

2021-04-25

·

Updated

2024-03-06

·

CVE-2021-31864

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Redmine versions prior to 4.0.9 Redmine versions 4.1.x prior to 4.1.3 Redmine versions 4.2.x prior to 4.2.1
Description The issue allows attackers to bypass the add issue notes permission requirement by leveraging the incoming mail handler. This can enable a remote attacker to impact data integrity.
Recommendations For Redmine versions prior to 4.0.9, update to version 4.0.9 or later. For Redmine versions 4.1.x prior to 4.1.3, update to version 4.1.3 or later. For Redmine versions 4.2.x prior to 4.2.1, update to version 4.2.1 or later.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2021-05240
BIT-REDMINE-2021-31864
CVE-2021-31864
DLA-2658-1

Affected Products

Redmine