Описание
Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensitive information.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| redmine | fixed | 3.4.2-1 | package | |
| redmine | end-of-life | jessie | package | |
| redmine | end-of-life | wheezy | package |
Примечания
https://www.redmine.org/projects/redmine/wiki/Security_Advisories
https://www.redmine.org/issues/23803 (private)
upstream fixed in 3.2.6 and 3.3.3
Связанные уязвимости
Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensitive information.
Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensitive information.
Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensitive information.