PT-2021-7937 · Redmine · Redmine
Felix Schäfer
+1
·
Published
2021-08-05
·
Updated
2024-03-06
·
CVE-2021-37156
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Redmine versions 4.2.0 through 4.2.1
Description
The issue is related to the incorrect session expiration in Redmine, a web application for project and task management. When two-factor authentication is enabled for a user's account, existing user sessions are not terminated as intended, allowing them to continue. This could potentially be exploited by a remote attacker to continue accessing the user's account without proper authentication.
Recommendations
For Redmine versions 4.2.0 and 4.2.1, consider terminating all existing user sessions immediately after enabling two-factor authentication for the user's account as a temporary workaround.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Redmine