Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performing a CSV export and reading time entries.
| Software | From | Fixed in |
|---|---|---|
| redmine / redmine | 4.1.0 | 4.1.1 |
| redmine / redmine | - | 4.0.7 |
| debian / debian_linux | 9.0 | 9.0.x |