CVE Vulnerabilities

CVE-2021-31865

Published: Apr 28, 2021 | Modified: Jul 12, 2022
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows users to circumvent the allowed filename extensions of uploaded attachments.

Affected Software

Name Vendor Start Version End Version
Redmine Redmine * 4.0.9 (excluding)
Redmine Redmine 4.1.0 (including) 4.1.3 (excluding)
Redmine Redmine 4.2.0 (including) 4.2.1 (excluding)

References