Information disclosure in Redmine - CVE-2021-31866
Published: May 4, 2021
Redmine
Ruby
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote attacker can learn the values of internal authentication keys by observing timing differences in string comparison operations within SysController and MailHandlerController.