CVE-2021-31865: Medium severity redmine vulnerability
Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows users to circumvent the allowed filename extensions of uploaded attachments.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-31865?
CVE-2021-31865 is a vulnerability in Redmine versions before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 that allows users to bypass the allowed filename extensions for uploaded attachments.
How severe is CVE-2021-31865?
CVE-2021-31865 has a severity rating of 5.3 (Medium).
How can I fix CVE-2021-31865?
To fix CVE-2021-31865, you should update Redmine to version 4.0.9, 4.1.3, or 4.2.1, depending on your currently installed version.
Where can I find more information about CVE-2021-31865?
You can find more information about CVE-2021-31865 in the Debian LTS Announcement and the Redmine Security Advisories.
What software versions are affected by CVE-2021-31865?
Redmine versions before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 are affected by CVE-2021-31865, as well as Debian Linux version 9.0.