ZeroHour

CVE-2021-31863

CVSS 3.1
7.5 high
EPSS
2%p76
Published
()
Modified
Description

Insufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows Redmine users to read arbitrary local files accessible by the application server process.

Vendors
redminedebian
Products
redmine, debian linux
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.