The Issues API in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote authenticated users to obtain sensitive information in changeset messages by leveraging permission to read issues with related changesets from other projects.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2016-04-12T14:00:00

Updated: 2024-08-06T08:20:41.872Z

Reserved: 2015-12-04T00:00:00

Link: CVE-2015-8473

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2016-04-12T14:59:04.193

Modified: 2016-04-20T19:26:11.517

Link: CVE-2015-8473

cve-icon Redhat

No data.