VYPR
Unrated severityNVD Advisory· Published Apr 28, 2021· Updated Aug 3, 2024

CVE-2021-31866

CVE-2021-31866

Description

Redmine before 4.0.9 and 4.1.x before 4.1.3 allows an attacker to learn the values of internal authentication keys by observing timing differences in string comparison operations within SysController and MailHandlerController.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.