Описание
Redmine before 4.1.5 and 4.2.x before 4.2.3 may disclose the names of users on activity views due to an insufficient access filter.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| redmine | fixed | 5.0.0-1 | package |
Примечания
https://www.redmine.org/news/133
https://www.redmine.org/projects/redmine/wiki/Changelog_4_1#415-2021-10-10
https://www.redmine.org/projects/redmine/wiki/Changelog_4_2#423-2021-10-10
https://www.redmine.org/projects/redmine/repository/revisions/21209
Связанные уязвимости
Redmine before 4.1.5 and 4.2.x before 4.2.3 may disclose the names of users on activity views due to an insufficient access filter.
Redmine before 4.1.5 and 4.2.x before 4.2.3 may disclose the names of users on activity views due to an insufficient access filter.
Redmine before 4.1.5 and 4.2.x before 4.2.3 may disclose the names of users on activity views due to an insufficient access filter.
Уязвимость веб-приложения для управления проектами и задачами Redmine, связанная с раскрытием информации, позволяющая нарушителю получить доступ к конфиденциальным данным