On Thursday, August 6, 2026 9:04:10 PM Mountain Standard Time Salvatore 
Bonaccorso wrote:
> Hi,
> 
> On Fri, Aug 07, 2026 at 02:35:03AM +0000, Debian Bug Tracking System wrote:
> >    [ Soren Stoutner ]
> >    * New upstream version (closes: #1140483 - CVE-2026-1836).
> 
> Is there more information on the fix? Can you point us to it? The
> original tracking only hat the incibe.es posting:
> https://www.incibe.es/en/incibe-cert/notices/aviso/stored-credentials-redmine
> which unfortunately is bit light on details apart only saying which
> version is fixed.

Upstream is light on public information about this fix.  The changelog says 
this:

"Defect #42998: Username and password stored in login form"

https://www.redmine.org/projects/redmine/wiki/Changelog_6_0

The commits that fix this CVE are here:

https://github.com/search?
q=repo%3Aredmine%2Fredmine+merge%3Afalse+42998&type=commits

-- 
Soren Stoutner
[email protected]

Attachment: signature.asc
Description: This is a digitally signed message part.

Reply via email to