First published: Wed Apr 28 2021(Updated: )
Redmine before 4.0.9 and 4.1.x before 4.1.3 allows an attacker to learn the values of internal authentication keys by observing timing differences in string comparison operations within SysController and MailHandlerController.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Redmine Redmine | <4.0.9 | |
Redmine Redmine | >=4.1.0<4.1.3 | |
Debian Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-31866 is a vulnerability in Redmine before 4.0.9 and 4.1.x before 4.1.3 that allows an attacker to learn the values of internal authentication keys.
CVE-2021-31866 works by observing timing differences in string comparison operations within SysController and MailHandlerController in Redmine.
CVE-2021-31866 has a severity rating of medium with a score of 5.3.
Redmine versions before 4.0.9 and 4.1.x before 4.1.3 are affected by CVE-2021-31866.
To fix CVE-2021-31866, users should upgrade to Redmine version 4.0.9 or 4.1.3.