Medium severity5.3NVD Advisory· Published Apr 28, 2021· Updated Jun 17, 2026
CVE-2021-31865
CVE-2021-31865
Description
Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows users to circumvent the allowed filename extensions of uploaded attachments.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5Patches
Vulnerability mechanics
References
3- lists.debian.org/debian-lts-announce/2021/05/msg00013.htmlnvdMailing ListThird Party Advisory
- www.redmine.org/news/131nvdVendor Advisory
- www.redmine.org/projects/redmine/wiki/Security_AdvisoriesnvdVendor Advisory
News mentions
0No linked articles in our index yet.