Impact
The Redmine application stores usernames and passwords after login. This flaw results in stored credential data that can be read by any user with platform access. The vulnerability is a CWE‑257 exposure of data that can lead to credential theft and account hijacking, compromising confidentiality of user credentials.
Affected Systems
Redmine belongs to the Redmine product line. Instances running any version older than 6.0.7, 5.1.10 or 5.0.14 are affected. The issue is documented for Redmine 5.0 through 5.1 and for 6.0 releases prior to the fixed versions.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector requires local or network access to the Redmine instance, with an attacker needing sufficient privileges to view the stored credential data. The impact is exposure of login credentials that could be used for unauthorized account access.
OpenCVE Enrichment