CVE-2015-8346
MEDIUMRedmine <2.6.8, <3.0.6, <3.1.2 - Info Disclosure
Title source: llmDescription
app/views/timelog/_form.html.erb in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote attackers to obtain sensitive information about subjects of issues by viewing the time logging form.
Scores
CVSS v3
5.3
EPSS
0.0046
EPSS Percentile
64.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Classification
CWE
CWE-199
Status
draft
Affected Products (10)
redmine/redmine
< 2.6.7
redmine/redmine
redmine/redmine
redmine/redmine
redmine/redmine
redmine/redmine
redmine/redmine
redmine/redmine
redmine/redmine
debian/debian_linux
Timeline
Published
Apr 12, 2016
Tracked Since
Feb 18, 2026