| Vulnerability Name: | CVE-2021-31863 (CCN-200955) | ||||||||||||
| Assigned: | 2021-04-28 | ||||||||||||
| Published: | 2021-04-28 | ||||||||||||
| Updated: | 2021-06-01 | ||||||||||||
| Summary: | Insufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows Redmine users to read arbitrary local files accessible by the application server process. | ||||||||||||
| CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||
| Vulnerability Type: | CWE-20 | ||||||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2021-31863 Source: XF Type: UNKNOWN redmine-cve202131863-info-disc(200955) Source: MLIST Type: Mailing List, Third Party Advisory [debian-lts-announce] 20210513 [SECURITY] [DLA 2658-1] redmine security update Source: MISC Type: Vendor Advisory https://www.redmine.org/news/131 Source: CCN Type: Redmine Web site Redmine Security Advisories Source: MISC Type: Vendor Advisory https://www.redmine.org/projects/redmine/wiki/Security_Advisories Source: CCN Type: WhiteSource Vulnerability Database CVE-2021-31863 | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||