Information Disclosure Vulnerability in Redmine by Redmine
CVE-2020-36308
5.3MEDIUM
What is CVE-2020-36308?
In versions of Redmine prior to 4.0.7 and 4.1.x prior to 4.1.1, an information disclosure vulnerability exists that permits attackers to access non-visible issue subjects. This can be exploited by leveraging CSV exports and examining time entries, resulting in unintended data exposure. Organizations utilizing these affected versions should update to mitigate potential risks.
