CVE-2015-8346

MEDIUM

Redmine <2.6.8, <3.0.6, <3.1.2 - Info Disclosure

Title source: llm

Description

app/views/timelog/_form.html.erb in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote attackers to obtain sensitive information about subjects of issues by viewing the time logging form.

Scores

CVSS v3 5.3
EPSS 0.0046
EPSS Percentile 64.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-199
Status draft

Affected Products (10)

redmine/redmine < 2.6.7
redmine/redmine
redmine/redmine
redmine/redmine
redmine/redmine
redmine/redmine
redmine/redmine
redmine/redmine
redmine/redmine
debian/debian_linux

Timeline

Published Apr 12, 2016
Tracked Since Feb 18, 2026