Medium severity5.3NVD Advisory· Published Apr 6, 2021· Updated Jun 17, 2026
CVE-2020-36308
CVE-2020-36308
Description
Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performing a CSV export and reading time entries.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5Patches
Vulnerability mechanics
References
2- lists.debian.org/debian-lts-announce/2021/05/msg00013.htmlnvdMailing ListThird Party Advisory
- www.redmine.org/projects/redmine/wiki/Security_AdvisoriesnvdNot Applicable
News mentions
0No linked articles in our index yet.