User Information Disclosure in Redmine by Redmine
CVE-2021-42326

5.3MEDIUM

Key Information:

Vendor

Redmine

Status
Vendor
CVE Published:
12 October 2021

What is CVE-2021-42326?

Redmine versions prior to 4.1.5 and 4.2.3 exhibit a security flaw where insufficient access filtering can lead to the disclosure of user names through activity views. This vulnerability may allow unauthorized users to view sensitive user information, potentially compromising user privacy. It is essential for users running affected versions to upgrade to the latest releases to mitigate these security risks.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.