VDB

CVE-2021-31863

CVE-2021-31863 PUBLISHED

Insufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows Redmine users to read arbitrary local files accessible by the application server process.

EPSS 0.79% · 74.3th percentile

Risk Scores

EPSS Score
0.79%
74.3th percentile

Affected Products

VendorProductVersions
Bitnamiredmine0, 4.1.0, 4.2.0
Bitnamiredmine4.1.0, 4.2.0, 0

Timeline

  • Apr 28, 2021 EPSS Score
  • Apr 28, 2021 CVE Published
  • Jul 1, 2021 EPSS Score
  • Sep 1, 2021 EPSS Score
  • Nov 3, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Mar 7, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 8, 2022 EPSS Score
  • Jul 10, 2022 EPSS Score
  • Sep 11, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›