Insufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows Redmine users to read arbitrary local files accessible by the application server process.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-2658-1 redmine security update
EUVD EUVD EUVD-2021-18738 Insufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows Redmine users to read arbitrary local files accessible by the application server process.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-03T23:10:30.812Z

Reserved: 2021-04-28T00:00:00

Link: CVE-2021-31863

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-04-28T07:15:07.583

Modified: 2024-11-21T06:06:22.713

Link: CVE-2021-31863

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.