#1140483 redmine: CVE-2026-1836

Package:
src:redmine
Source:
src:redmine
Submitter:
Salvatore Bonaccorso
Date:
2026-08-07 13:39:02 UTC
Severity:
normal
Tags:
#1140483#5
Date:
2026-06-21 11:51:36 UTC
From:
To:
Hi,

The following vulnerability was published for redmine.

CVE-2026-1836[0]:
| The system stores the username and password from the login form
| after submitting the request. This could allow an attacker with
| access to the platform to return to the browser and view the login
| credentials.

Unfortunately the only reference is [1], which only heps with the
fixed verisons indications. So 6.0.7, 5.1.10 and 5.0.14 contain the
fix apparently.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-1836
https://www.cve.org/CVERecord?id=CVE-2026-1836
[1] https://www.incibe.es/en/incibe-cert/notices/aviso/stored-credentials-redmine

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1140483#10
Date:
2026-08-07 02:34:19 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
redmine, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1140483@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Soren Stoutner <soren@debian.org> (supplier of updated redmine package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 06 Aug 2026 18:24:04 -0700
Source: redmine
Architecture: source
Version: 6.1.3+ds-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Ruby Team <pkg-ruby-extras-maintainers@lists.alioth.debian.org>
Changed-By: Soren Stoutner <soren@debian.org>
Closes: 1127718 1140483
Changes:
 redmine (6.1.3+ds-1) unstable; urgency=medium
 .
   [ Soren Stoutner ]
   * New upstream version (closes: #1140483 - CVE-2026-1836).
   * Move debian/doc/examples/ to debian/examples/.
   * Rename debian/examples to debian/redmine.examples and change contents to
     install from debian/examples/.
   * Add debian/source/lintian-overrides.
   * Add debian/README.source to document the CRLF issue.
   * debian/patches/add-multi-tenancy-support.patch:  Refresh offsets.
   * debian/patches/autoload-thin-gem.patch:  Refresh offset.
   * debian/patches/fix-sanitation-tests.patch:  Refresh offsets.
   * debian/patches/gemfile-deps-adjustment.patch:  Update for latest release.
   * debian/patches/use-system-jquery-libs.patch:  Refresh fuzz and offset.
   * debian/control:  Update the following Build-Dependency and Dependency:
     - Bump Standards-Version from 4.7.3 to 4.7.4, no changes needed.
     - Add ruby-bcrypt.
     - Add ruby-oauth2.
     - Add ruby-rest-client.
     - Add ruby-doorkeeper (>= 5.9.3), (<< 5.10).
     - Add ruby-doorkeeper-i18n (>= 5.2), (<< 5.3).
     - Add ruby-importmap-rails (>= 2.0), (<< 3).
     - Add ruby-minitest (>= 5.27), (<< 6.1).
     - Add ruby-requestjs-rails (>= 0.0.13), (<< 0.1.0).
     - Add ruby-stimulus-rails (>= 1.3), (<< 2.0).
     - Bump debhelper-compat from version 13 to 14, dropping now unnecessary
       ${misc:Depends}.
     - Bump ruby-commonmarker from (>= 0.23.8), (<< 0.24) to (>= 2.8.3),
       (<< 2.9).
     - Bump ruby-i18n from ruby-i18n (>= 1.14.1), (<< 1.15) to (>= 1.15.2),
          (<< 1.16).
     - Bump ruby-mail from (>= 2.8.1~), (<< 2.9) to (>= 2.9.1), (<< 2.10)
       (closes: #1127718).
     - Bump ruby-minitest from (>= 5.27), (<< 6.1) to (>= 6.0), (<< 7)
     - Bump ruby-nokogiri from (>= 1.18.3), (<< 1.19) to (>= 1.19.1), (<< 1.20).
     - Bump ruby-rails from (>= 2:7.2), (<< 2:8.0) to (>= 2:7.2.3), (<< 2:7.3).
     - Bump ruby-rbpdf from (>= 1.21.3~) to (>= 1.21.4).
     - Bump ruby-rouge from (>= 4.5), (<< 5.0) to (>= 5.0), (<< 6).
     - Bump ruby-sqlite3 from (>= 1.7.0), (<< 1.8) to (>= 2.9.0), (<< 2.10.0).
     - Bump ruzy-zip from (>= 3.2.2), (<< 3.3) to (>= 3.4.1), (<< 3.5).
     - Change ruby-rack (>= 3.1.3~), (<< 3.2) to ruby-rack (>= 3.1.3) to match
       the Gemfile.
     - Remove unnecessary ~ from the version constraints.
     - Drop the unnecessary dependency on ruby-simplecov.
   * debian/copyright:
     - Bump my copyright years to be 2024-2026.
     - Update app/assets/ stanza to match new upstream release.
   * debian/README.Debian:  Fix typos.
   * debian/readmine.lintian-overrides.  Add override for
     package-contains-empty-directory.
   * debian/rules:
     - Make the new /usr/share/rebmine/bin/importmap executable.
     - Remove the example plugin.
     - Remove unnecessary double-upstream README file.
     - Remove "FIXME" from comment and replace with an explanation of the file
       permission modification (fixes a lintian info tag).
   * debian/watch:  Update to version 5.
 .
   [ Lucas Nussbaum ]
   * Remove unnecessary debian/.gitattributes.
Checksums-Sha1:
 4a3eef7ba9a6a0bb89e580b445ee3f13dd35687d 4121 redmine_6.1.3+ds-1.dsc
 36a4f5ae4b1eceff866ccd119e2733830b8ebfc6 2905280 redmine_6.1.3+ds.orig.tar.xz
 02ff058797f7dd6ae936d91043d6e3122a7ca871 101108 redmine_6.1.3+ds-1.debian.tar.xz
 5bb48366dd57abeb60972bd22ec9a3a90103a490 13096 redmine_6.1.3+ds-1_amd64.buildinfo
Checksums-Sha256:
 9bfea8e8f8add5f1007f5d0282c1be4cc8cd56189bfca33c6964208c8be47635 4121 redmine_6.1.3+ds-1.dsc
 01f868f82feaf25c298b7c2e3471da63f36e07d104e33d4c8e52817ce5d323df 2905280 redmine_6.1.3+ds.orig.tar.xz
 7aba41195e3f49522e56680b9950fc920beadb332a77bd1e33f2e68b3db97f45 101108 redmine_6.1.3+ds-1.debian.tar.xz
 3882f0b6f32545d3e8a37a714950f2aed9be1e6642f354b5e57deee39983d3a1 13096 redmine_6.1.3+ds-1_amd64.buildinfo
Files:
 16d7a68afeb0ef46281ee27139098131 4121 web optional redmine_6.1.3+ds-1.dsc
 484ca8e8989cb30bece3f691f2fc8f37 2905280 web optional redmine_6.1.3+ds.orig.tar.xz
 b0eeeabd5437c6466fd5542c859ddcb3 101108 web optional redmine_6.1.3+ds-1.debian.tar.xz
 52f6ddfb0a8a9960cfdacf31f87784f3 13096 web optional redmine_6.1.3+ds-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEJKVN2yNUZnlcqOI+wufLJ66wtgMFAmp1QWoACgkQwufLJ66w
tgO7PQ/+ObSrOkLhW2XmbA7kRYtEA6Cv4xkIF/zk+kY+vygV3T985vitkZxXCBku
+D43Xplq1D9qSpJHQC3YLa9s/lmzmslq3j6lBk/cPeUSElEWNOrtyykEDYhjlYZa
PwNgLdZIYOVowx1WU18aa+G3C62JVYIdXE6kaKXppGut197OcmgbsxpYGwKhC3Jm
Imc/rgDxAyHoET1hwXvIndvpOKhFW5V59sUX0eFCwNZRSI3epNf3ybK1HXq6YTrB
oQeTJww/70G4D0+S3fmQz5F0Kz/P/vBNjNf9ViuKU1J8z2EviMm8tPCsz7wiEXAO
ey5w9VXLnJB4+qyGjS6+qxlVNCzSVbC0v6MdJBjvE+csq+eYUEetEaKF2xbbCTC6
l5jUqAFF3qy6jtGlSXaUjno6rv7O/Mc9iiYNlUD/3L8d27tIU795QGKAFIofuZpx
CYY9bIHTx+AKmjmefPE9J+EDo9WxARfyosBJQusAkkZfsifv2h9MHwgUTA9aSgJR
H5+RvV2ZSaUCa5nFL1UpAX65acjw+g5xOo5RTZZSqEMf+E+Q99oOXlLD2Lt7cnXk
vP69aaT4ZEN8STFyuu3NL+KitaLuzNtJ8sBvetJ8yZxZ07Ayh1yrJKtVtiEg7MSW
EGPTAJuNbyZ69HOpjuwnyuVOsQDCg4We0HNL32qWRqafD+1ay7I=
=R1or
-----END PGP SIGNATURE-----

#1140483#15
Date:
2026-08-07 04:04:10 UTC
From:
To:
Hi,

Is there more information on the fix? Can you point us to it? The
original tracking only hat the incibe.es posting:
https://www.incibe.es/en/incibe-cert/notices/aviso/stored-credentials-redmine
which unfortunately is bit light on details apart only saying which
version is fixed.

Regards,
Salvatore

#1140483#20
Date:
2026-08-07 04:18:15 UTC
From:
To:
On Thursday, August 6, 2026 9:04:10 PM Mountain Standard Time Salvatore Bonaccorso wrote:

Upstream is light on public information about this fix.  The changelog says
this:

"Defect #42998: Username and password stored in login form"

https://www.redmine.org/projects/redmine/wiki/Changelog_6_0

The commits that fix this CVE are here:

https://github.com/search?
q=repo%3Aredmine%2Fredmine+merge%3Afalse+42998&type=commits

#1140483#25
Date:
2026-08-07 04:28:32 UTC
From:
To:
On Thursday, August 6, 2026 9:18:15 PM Mountain Standard Time Soren Stoutner wrote:
wrote:

If you are asking what the original flaw entailed, it was that browsers would
cache the authentication fields until the browser was closed.  So, if someone
logged into a Redmine instance using a public computer, logged out, but then
*didn’t close the browser*, it would be possible for the next user to extract
the authentication information from the browser.  The fix is to mark the
fields as "no-store" to the Cache-Control header.

Although this attack vector is a possibility, prior to the fix it could be
mitigated by the user if they closed the browser on a shared machine after
logging out.

#1140483#30
Date:
2026-08-07 13:36:47 UTC
From:
To:
Hi,

Thanks!

Regards,
Salvatore