CVE-2021-31866: Medium severity redmine vulnerability
Redmine before 4.0.9 and 4.1.x before 4.1.3 allows an attacker to learn the values of internal authentication keys by observing timing differences in string comparison operations within SysController and MailHandlerController.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-31866?
CVE-2021-31866 is a vulnerability in Redmine before 4.0.9 and 4.1.x before 4.1.3 that allows an attacker to learn the values of internal authentication keys.
How does CVE-2021-31866 work?
CVE-2021-31866 works by observing timing differences in string comparison operations within SysController and MailHandlerController in Redmine.
What is the severity of CVE-2021-31866?
CVE-2021-31866 has a severity rating of medium with a score of 5.3.
Which software versions are affected by CVE-2021-31866?
Redmine versions before 4.0.9 and 4.1.x before 4.1.3 are affected by CVE-2021-31866.
How can I fix CVE-2021-31866?
To fix CVE-2021-31866, users should upgrade to Redmine version 4.0.9 or 4.1.3.