CVE Vulnerabilities

CVE-2015-8346

Published: Apr 12, 2016 | Modified: Apr 12, 2025
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

app/views/timelog/_form.html.erb in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote attackers to obtain sensitive information about subjects of issues by viewing the time logging form.

Affected Software

NameVendorStart VersionEnd Version
RedmineRedmine*2.6.7 (including)
RedmineRedmine3.0.0 (including)3.0.0 (including)
RedmineRedmine3.0.1 (including)3.0.1 (including)
RedmineRedmine3.0.2 (including)3.0.2 (including)
RedmineRedmine3.0.3 (including)3.0.3 (including)
RedmineRedmine3.0.4 (including)3.0.4 (including)
RedmineRedmine3.0.5 (including)3.0.5 (including)
RedmineRedmine3.1.0 (including)3.1.0 (including)
RedmineRedmine3.1.1 (including)3.1.1 (including)
RedmineUbuntuprecise*
RedmineUbuntutrusty*
RedmineUbuntuupstream*
RedmineUbuntuvivid*
RedmineUbuntuwily*
RedmineUbuntuyakkety*
RedmineUbuntuzesty*

References