← Vulnerability feed

Vulnerability record · CVE-2021-37156 · published 5 August 2021

CVE-2021-37156: Redmine insufficient session expiration vulnerability

Redmine · Redmine

Redmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling two-factor authentication for the user's account, but the intended behavior is for those sessions to be terminated.

7.5 CVSS 3.1 High EPSS 1.0% · top 38.2% CWE-613 · Insufficient session expiration
7.5CVSS 3.1 base score, v2 5.0
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Redmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling two-factor authentication for the user's account, but the intended behavior is for those sessions to be terminated.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-37156 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-30164Redmine vulnerabilityRedmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_issue_notes permission requirement by leveraging the Issues API.EPSS 1.3%8.8CVE-2017-18026Redmine vulnerabilityRedmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which …EPSS 2.8%7.5CVE-2022-44030Redmine vulnerabilityRedmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the…EPSS 0.66%7.5CVE-2021-31863Redmine improper input validation vulnerabilityInsufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows Redmine us…EPSS 1.7%7.5CVE-2021-30163Redmine vulnerabilityRedmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the names of private projects if issue-journal details exist that have chang…EPSS 1.2%7.5CVE-2017-15572Redmine sensitive information in log file vulnerabilityIn Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sensitive information (password reset tokens) by reading a Referer log, b…EPSS 2.4%7.5CVE-2017-15576Redmine information exposure vulnerabilityRedmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensitive info…EPSS 1.6%7.5CVE-2017-15577Redmine information exposure vulnerabilityRedmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows remote attackers to obtain sensitive information.EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2021-37156), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.