Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c2rv-c7wr-4chh

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function in app/models/mailer.rb does not check whether an issue is visible, which allows remote authenticated users to obtain sensitive information by reading e-mail reminder messages.

In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function in app/models/mailer.rb does not check whether an issue is visible, which allows remote authenticated users to obtain sensitive information by reading e-mail reminder messages.

EPSS

Процентиль: 57%
0.00345
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 8 лет назад

In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function in app/models/mailer.rb does not check whether an issue is visible, which allows remote authenticated users to obtain sensitive information by reading e-mail reminder messages.

CVSS3: 4.3
nvd
около 8 лет назад

In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function in app/models/mailer.rb does not check whether an issue is visible, which allows remote authenticated users to obtain sensitive information by reading e-mail reminder messages.

CVSS3: 4.3
debian
около 8 лет назад

In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function ...

EPSS

Процентиль: 57%
0.00345
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200