CVE-2021-31866
Last modified
CVE-2021-31866 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Redmine before 4.0.9 and 4.1.x before 4.1.3 allows an attacker to learn the values of internal authentication keys by observing timing differences in string comparison operations within SysController and MailHandlerController.. EPSS estimates a 1.21% chance of exploitation in the next 30 days.
Description
Redmine before 4.0.9 and 4.1.x before 4.1.3 allows an attacker to learn the values of internal authentication keys by observing timing differences in string comparison operations within SysController and MailHandlerController.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redmine | Redmine | < 4.0.9 |
| Redmine | Redmine | >= 4.1.0, < 4.1.3 |
| Debian | Debian Linux | 9.0 |
References
- https://lists.debian.org/debian-lts-announce/2021/05/msg00013.htmlMailing List, Third Party Advisory
- https://www.redmine.org/news/131Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2021/05/msg00013.htmlMailing List, Third Party Advisory
- https://www.redmine.org/news/131Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-31866?
How severe is CVE-2021-31866?
How do I fix CVE-2021-31866?
Are you affected by CVE-2021-31866?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
