AVG-2462 log

Package redmine
Status Fixed
Severity Medium
Type information disclosure
Affected 4.2.2-2
Fixed 4.2.3-1
Current 5.1.3-2 [extra]
Ticket FS#72728
Created Wed Oct 13 08:47:55 2021
Issue Severity Remote Type Description
CVE-2021-42326 Medium Yes Information disclosure
Redmine before 4.2.3 may disclose the names of users on activity views due to an insufficient access filter.