app/views/timelog/_form.html.erb in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote attackers to obtain sensitive information about subjects of issues by viewing the time logging form.
Weaknesses in this category are related to improper handling of sensitive information.
Link | Tags |
---|---|
https://www.redmine.org/issues/21150 | |
http://www.redmine.org/news/102 | patch vendor advisory |
http://www.debian.org/security/2016/dsa-3529 | vendor advisory |
https://github.com/redmine/redmine/commit/c096dde88ff02872ba35edc4dc403c80a7867b5c |