ZeroHour

CVE-2021-31865

CVSS 3.1
5.3 medium
EPSS
1%p65
Published
()
Modified
Description

Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows users to circumvent the allowed filename extensions of uploaded attachments.

Vendors
redminedebian
Products
redmine, debian linux
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.