CVE-2021-42326
12.10.2021, 19:15
Redmine before 4.1.5 and 4.2.x before 4.2.3 may disclose the names of users on activity views due to an insufficient access filter.Enginsight
| Vendor | Product | Version |
|---|---|---|
| redmine | redmine | 𝑥 < 4.1.5 |
| redmine | redmine | 4.2.0 ≤ 𝑥 < 4.2.3 |
| debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References