CVE-2021-31866
28.04.2021, 07:15
Redmine before 4.0.9 and 4.1.x before 4.1.3 allows an attacker to learn the values of internal authentication keys by observing timing differences in string comparison operations within SysController and MailHandlerController.Enginsight
| Vendor | Product | Version |
|---|---|---|
| redmine | redmine | 𝑥 < 4.0.9 |
| redmine | redmine | 4.1.0 ≤ 𝑥 < 4.1.3 |
| debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References