Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 817686 - www-apps/redmine: Multiple vulnerabilties
Summary: www-apps/redmine: Multiple vulnerabilties
Status: RESOLVED DUPLICATE of bug 817917
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~4 [ebuild]
Keywords:
Depends on:
Blocks:
 
Reported: 2021-10-11 03:31 UTC by Sam James
Modified: 2021-10-13 01:59 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-10-11 03:31:41 UTC
From the 4.1.5 and 4.2.3 release notes:
```
[Security]
    Defect #35789: Redmine is leaking usernames on activities index view
    Patch #35463: Enforce stricter class filtering in WatchersController
```

https://www.redmine.org/projects/redmine/wiki/Changelog_4_2
https://www.redmine.org/projects/redmine/wiki/Changelog_4_1
Comment 1 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-10-13 01:59:03 UTC
We'll use the other one given it's got the CVE.

*** This bug has been marked as a duplicate of bug 817917 ***