VYPR
Unrated severityNVD Advisory· Published Apr 6, 2021· Updated Aug 4, 2024

CVE-2020-36308

CVE-2020-36308

Description

Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performing a CSV export and reading time entries.

Affected products

2

Patches

2
e1a783af455a

tagged version 4.1.1

https://github.com/redmine/redmineJean-Philippe LangApr 6, 2020via osv
5a5692ebc935

tagged version 4.0.7

https://github.com/redmine/redmineJean-Philippe LangApr 6, 2020via osv

Vulnerability mechanics

Generated on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

2

News mentions

0

No linked articles in our index yet.