VulnerabilityModified
CVE-2021-42326
Redmine before 4.1.5 and 4.2.x before 4.2.3 may disclose the names of users on activity views due to an insufficient access filter.
MEDIUM 5.3EPSS 1.17%
Does this matter?
Lower severity and a low EPSS score (1.17%). Track it; it rarely justifies an emergency change on its own.
Description
Redmine before 4.1.5 and 4.2.x before 4.2.3 may disclose the names of users on activity views due to an insufficient access filter.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.17% probability · 65th percentile
- CISA KEV
- Not listed
- Affected
- redmine/redmine · debian/debian linux
- Source
- cve@mitre.org
References
- https://lists.debian.org/debian-lts-announce/2021/10/msg00013.htmlThird Party Advisory
- https://www.redmine.org/news/133Mitigation, Vendor Advisory
- https://www.redmine.org/projects/redmine/wiki/Changelog_4_1#415-2021-10-10Release Notes, Vendor Advisory
- https://www.redmine.org/projects/redmine/wiki/Changelog_4_2#423-2021-10-10Release Notes, Vendor Advisory
- https://www.redmine.org/projects/redmine/wiki/Security_AdvisoriesPatch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2021/10/msg00013.htmlThird Party Advisory
- https://www.redmine.org/news/133Mitigation, Vendor Advisory
- https://www.redmine.org/projects/redmine/wiki/Changelog_4_1#415-2021-10-10Release Notes, Vendor Advisory
- https://www.redmine.org/projects/redmine/wiki/Changelog_4_2#423-2021-10-10Release Notes, Vendor Advisory
- https://www.redmine.org/projects/redmine/wiki/Security_AdvisoriesPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.