Related Vulnerabilities: CVE-2021-31864  

Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows attackers to bypass the add_issue_notes permission requirement by leveraging the incoming mail handler.

Severity Low

Remote Yes

Type Access restriction bypass

Description

Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows attackers to bypass the add_issue_notes permission requirement by leveraging the incoming mail handler.

AVG-1886 redmine 4.2.0-1 Critical Vulnerable

https://www.redmine.org/projects/redmine/wiki/Security_Advisories
https://www.redmine.org/issues/35045
https://github.com/redmine/redmine/commit/d03a718e6efca0493d8b42bd4ba356d736a77f49