CVE Vulnerabilities

CVE-2021-31865

Published: Apr 28, 2021 | Modified: Jul 12, 2022
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows users to circumvent the allowed filename extensions of uploaded attachments.

Affected Software

Name Vendor Start Version End Version
Redmine Redmine * 4.0.9 (excluding)
Redmine Redmine 4.1.0 (including) 4.1.3 (excluding)
Redmine Redmine 4.2.0 (including) 4.2.1 (excluding)
Redmine Ubuntu bionic *
Redmine Ubuntu groovy *
Redmine Ubuntu kinetic *
Redmine Ubuntu lunar *
Redmine Ubuntu mantic *
Redmine Ubuntu trusty *
Redmine Ubuntu xenial *

References