[From nobody Fri Aug  7 03:35:07 2026
Received: (at submit) by bugs.debian.org; 21 Jun 2026 11:51:39 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-10.0 required=4.0 tests=BAYES_00,FROMDEVELOPER,
 NO_RELAYS,XMAILER_REPORTBUG autolearn=ham autolearn_force=no
 version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 24; hammy, 128; neutral, 37; spammy,
 3. spammytokens:0.941-+--H*r:bugs.debian.org, 0.938-+--view,
 0.854-+--browser hammytokens:0.000-+--H*F:U*carnil,
 0.000-+--XDebbugsCc, 0.000-+--X-Debbugs-Cc, 0.000-+--H*Ad:N*Bug,
 0.000-+--H*Ad:N*Tracking
Return-path: &lt;carnil@debian.org&gt;
Received: via submission by buxtehude.debian.org with esmtp (Exim 4.96)
 (envelope-from &lt;carnil@debian.org&gt;) id 1wbGi9-00CKBJ-1O
 for submit@bugs.debian.org; Sun, 21 Jun 2026 11:51:39 +0000
Content-Type: text/plain; charset=&quot;us-ascii&quot;
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: Salvatore Bonaccorso &lt;carnil@debian.org&gt;
To: Debian Bug Tracking System &lt;submit@bugs.debian.org&gt;
Subject: redmine: CVE-2026-1836
Message-ID: &lt;178204269645.54491.13789300200678592882.reportbug@eldamar.lan&gt;
X-Mailer: reportbug 13.2.0+nmu1
Date: Sun, 21 Jun 2026 13:51:36 +0200
Delivered-To: submit@bugs.debian.org

Source: redmine
Version: 6.0.6+ds-6
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil@debian.org, Debian Security Team &lt;team@security.debian.org&gt;

Hi,

The following vulnerability was published for redmine.

CVE-2026-1836[0]:
| The system stores the username and password from the login form
| after submitting the request. This could allow an attacker with
| access to the platform to return to the browser and view the login
| credentials.

Unfortunately the only reference is [1], which only heps with the
fixed verisons indications. So 6.0.7, 5.1.10 and 5.0.14 contain the
fix apparently.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities &amp; Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-1836
    https://www.cve.org/CVERecord?id=CVE-2026-1836
[1] https://www.incibe.es/en/incibe-cert/notices/aviso/stored-credentials-redmine

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore
]