CVE-2021-42326: Medium severity Redmine Redmine vulnerability
Redmine before 4.1.5 and 4.2.x before 4.2.3 may disclose the names of users on activity views due to an insufficient access filter.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-42326?
CVE-2021-42326 is a vulnerability in Redmine versions before 4.1.5 and 4.2.x before 4.2.3 that may disclose the names of users on activity views due to an insufficient access filter.
What is the severity of CVE-2021-42326?
CVE-2021-42326 has a severity rating of medium, with a CVSS score of 5.3.
How can CVE-2021-42326 be exploited?
CVE-2021-42326 can be exploited by viewing activity views in Redmine versions before 4.1.5 and 4.2.x before 4.2.3.
How can I fix CVE-2021-42326?
To fix CVE-2021-42326, it is recommended to upgrade Redmine to version 4.1.5 or apply the necessary patches for version 4.2.x before 4.2.3.
Where can I find more information about CVE-2021-42326?
More information about CVE-2021-42326 can be found on the Debian LTS announcements page and the Redmine website.