SB2021041215 - Multiple vulnerabilities in Ruby Redmine
Published: April 12, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Security features bypass (CVE-ID: CVE-2021-30164)
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the security restrictions bypass. A remote attacker can bypass the "add_issue_notes" permission requirement.
2) Information disclosure (CVE-ID: CVE-2021-30163)
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote attacker can discover the names of private projects if issue-journal details exist that have changes to project_id values.
Remediation
Install update from vendor's website.