PT-2021-7937 · Redmine · Redmine

Felix Schäfer

+1

·

Published

2021-08-05

·

Updated

2024-03-06

·

CVE-2021-37156

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Redmine versions 4.2.0 through 4.2.1
Description The issue is related to the incorrect session expiration in Redmine, a web application for project and task management. When two-factor authentication is enabled for a user's account, existing user sessions are not terminated as intended, allowing them to continue. This could potentially be exploited by a remote attacker to continue accessing the user's account without proper authentication.
Recommendations For Redmine versions 4.2.0 and 4.2.1, consider terminating all existing user sessions immediately after enabling two-factor authentication for the user's account as a temporary workaround. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

BDU:2023-05702
BIT-REDMINE-2021-37156
CVE-2021-37156

Affected Products

Redmine