PT-2021-7414 · Redmine · Redmine
Mischa The Evil
·
Published
2021-08-20
·
Updated
2024-03-06
·
CVE-2021-42326
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Redmine versions 4.1.5 and earlier
Redmine versions 4.2.x before 4.2.3
Description
The issue is related to an insufficient access filter, which may disclose the names of users on activity views. This allows a remote attacker to access confidential data.
Recommendations
For Redmine versions 4.1.5 and earlier, update to version 4.1.5 or later.
For Redmine versions 4.2.x before 4.2.3, update to version 4.2.3 or later.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Redmine