ZeroHour

CVE-2021-31866

CVSS 3.1
5.3 medium
EPSS
1%p67
Published
()
Modified
Description

Redmine before 4.0.9 and 4.1.x before 4.1.3 allows an attacker to learn the values of internal authentication keys by observing timing differences in string comparison operations within SysController and MailHandlerController.

Vendors
redminedebian
Products
redmine, debian linux
Weakness
CWE-203
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.