First published: Tue Oct 12 2021(Updated: )
Redmine before 4.1.5 and 4.2.x before 4.2.3 may disclose the names of users on activity views due to an insufficient access filter.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Redmine Redmine | <4.1.5 | |
Redmine Redmine | >=4.2.0<4.2.3 | |
Debian Debian Linux | =9.0 | |
<4.1.5 | ||
>=4.2.0<4.2.3 | ||
=9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-42326 is a vulnerability in Redmine versions before 4.1.5 and 4.2.x before 4.2.3 that may disclose the names of users on activity views due to an insufficient access filter.
CVE-2021-42326 has a severity rating of medium, with a CVSS score of 5.3.
CVE-2021-42326 can be exploited by viewing activity views in Redmine versions before 4.1.5 and 4.2.x before 4.2.3.
To fix CVE-2021-42326, it is recommended to upgrade Redmine to version 4.1.5 or apply the necessary patches for version 4.2.x before 4.2.3.
More information about CVE-2021-42326 can be found on the Debian LTS announcements page and the Redmine website.