CVE Vulnerabilities

CVE-2021-42326

Published: Oct 12, 2021 | Modified: Jun 28, 2022
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Redmine before 4.1.5 and 4.2.x before 4.2.3 may disclose the names of users on activity views due to an insufficient access filter.

Affected Software

Name Vendor Start Version End Version
Redmine Redmine * 4.1.5 (excluding)
Redmine Redmine 4.2.0 (including) 4.2.3 (excluding)
Redmine Ubuntu bionic *
Redmine Ubuntu kinetic *
Redmine Ubuntu lunar *
Redmine Ubuntu mantic *
Redmine Ubuntu trusty *
Redmine Ubuntu xenial *

References