CVE-2021-31863: Input Validation
Insufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows Redmine users to read arbitrary local files accessible by the application server process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-31863?
The severity of CVE-2021-31863 is high.
How does CVE-2021-31863 affect Redmine?
CVE-2021-31863 affects Redmine versions before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1.
What is the vulnerability description of CVE-2021-31863?
CVE-2021-31863 is an insufficient input validation vulnerability in the Git repository integration of Redmine, allowing users to read arbitrary local files accessible by the application server process.
How can I fix CVE-2021-31863 in Redmine?
To fix CVE-2021-31863, you should update your Redmine installation to version 4.0.9, 4.1.3, or 4.2.1.
Where can I find more information about CVE-2021-31863?
You can find more information about CVE-2021-31863 at the following references: [Link 1](https://lists.debian.org/debian-lts-announce/2021/05/msg00013.html), [Link 2](https://www.redmine.org/news/131), [Link 3](https://www.redmine.org/projects/redmine/wiki/Security_Advisories).