Candidate: CVE-2015-8346 PublicDate: 2016-04-12 14:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8346 https://www.redmine.org/projects/redmine/wiki/Changelog_3_0 https://www.redmine.org/projects/redmine/wiki/Security_Advisories http://www.openwall.com/lists/oss-security/2015/11/25/1 Description: app/views/timelog/_form.html.erb in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote attackers to obtain sensitive information about subjects of issues by viewing the time logging form. Ubuntu-Description: Notes: tyhicks> Fixed in 2.6.8, 3.0.6 and 3.1.2 Bugs: https://www.redmine.org/issues/21150 (private) http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=806376 Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N [5.3 MEDIUM] Patches_redmine: upstream_redmine: released (3.1.2) precise_redmine: ignored (reached end-of-life) precise/esm_redmine: DNE (precise was needed) trusty_redmine: ignored (reached end-of-life) trusty/esm_redmine: DNE (trusty was needed) vivid_redmine: ignored (reached end-of-life) vivid/stable-phone-overlay_redmine: DNE vivid/ubuntu-core_redmine: DNE wily_redmine: ignored (reached end-of-life) xenial_redmine: not-affected (3.2.0-1) yakkety_redmine: ignored (reached end-of-life) zesty_redmine: ignored (reached end-of-life) artful_redmine: not-affected (3.2.0-1) bionic_redmine: not-affected (3.2.0-1) cosmic_redmine: not-affected (3.2.0-1) disco_redmine: not-affected (3.2.0-1) devel_redmine: not-affected (3.2.0-1)