Insufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows Redmine users to read arbitrary local files accessible by the application server process.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-04-28T06:17:10

Updated: 2024-08-03T23:10:30.812Z

Reserved: 2021-04-28T00:00:00

Link: CVE-2021-31863

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-04-28T07:15:07.583

Modified: 2021-06-01T13:27:15.753

Link: CVE-2021-31863

cve-icon Redhat

No data.