CVE-2021-42326: Redmine before 4.1.5 and 4.2.x before 4.2.3 may disclose the names of users on activity views due to an insufficient access filter. Please bump.
*** Bug 817686 has been marked as a duplicate of this bug. ***
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=ba994378b56d87b15c84344466dae648484bd0d3 commit ba994378b56d87b15c84344466dae648484bd0d3 Author: Azamat H. Hackimov <azamat.hackimov@gmail.com> AuthorDate: 2021-10-15 11:51:05 +0000 Commit: Sam James <sam@gentoo.org> CommitDate: 2021-10-20 01:11:38 +0000 www-apps/redmine: new versions 4.1.5 and 4.2.3 Fix security issue CVE-2021-42326 Bug: https://bugs.gentoo.org/817917 Package-Manager: Portage-3.0.20, Repoman-3.0.3 Signed-off-by: Azamat H. Hackimov <azamat.hackimov@gmail.com> Signed-off-by: Sam James <sam@gentoo.org> www-apps/redmine/Manifest | 2 + www-apps/redmine/redmine-4.1.5.ebuild | 233 +++++++++++++++++++++++++++++++++ www-apps/redmine/redmine-4.2.3.ebuild | 240 ++++++++++++++++++++++++++++++++++ 3 files changed, 475 insertions(+)
Thanks, all done!