Vulnerabilities > CVE-2021-42326
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE Summary
Redmine before 4.1.5 and 4.2.x before 4.2.3 may disclose the names of users on activity views due to an insufficient access filter.
Vulnerable Configurations
References
- https://lists.debian.org/debian-lts-announce/2021/10/msg00013.html
- https://lists.debian.org/debian-lts-announce/2021/10/msg00013.html
- https://www.redmine.org/news/133
- https://www.redmine.org/news/133
- https://www.redmine.org/projects/redmine/wiki/Changelog_4_1#415-2021-10-10
- https://www.redmine.org/projects/redmine/wiki/Changelog_4_1#415-2021-10-10
- https://www.redmine.org/projects/redmine/wiki/Changelog_4_2#423-2021-10-10
- https://www.redmine.org/projects/redmine/wiki/Changelog_4_2#423-2021-10-10
- https://www.redmine.org/projects/redmine/wiki/Security_Advisories
- https://www.redmine.org/projects/redmine/wiki/Security_Advisories