Redmine before 4.0.9 and 4.1.x before 4.1.3 allows an attacker to learn the values of internal authentication keys by observing timing differences in string comparison operations within SysController and MailHandlerController.
                
            Metrics
Affected Vendors & Products
References
        History
                    No history.
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: mitre
Published: 2021-04-28T06:16:31
Updated: 2024-08-03T23:10:30.823Z
Reserved: 2021-04-28T00:00:00
Link: CVE-2021-31866
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Modified
Published: 2021-04-28T07:15:07.663
Modified: 2024-11-21T06:06:23.150
Link: CVE-2021-31866
 Redhat
                        Redhat
                    No data.