Changeflow GovPing Data Privacy & Cybersecurity CERT-FR: Multiple Redmine Vulnerabilities Ident...
Priority review Notice Added Final

CERT-FR: Multiple Redmine Vulnerabilities Identified

Favicon for www.cert.ssi.gouv.fr CERT-FR Security Advisories
Published March 17th, 2026
Detected March 17th, 2026
Email

Summary

CERT-FR has issued a security advisory regarding multiple vulnerabilities discovered in Redmine software. The vulnerabilities include Cross-Site Scripting (XSS) and security policy bypass, affecting specific versions of Redmine. Users are advised to consult the Redmine security advisories for patch information.

What changed

CERT-FR has published a security advisory (CERTFR-2026-AVI-0306) detailing multiple vulnerabilities found in Redmine software. The identified risks include security policy bypass, remote code injection (XSS), and other unspecified security issues. Affected versions are Redmine 6.0.x prior to 6.0.9, 6.1.x prior to 6.1.2, and all versions prior to 5.1.12.

Organizations using the affected Redmine versions must consult the official Redmine security advisories and apply the necessary patches to mitigate these risks. Failure to do so could lead to security breaches, including unauthorized code execution and policy circumvention. The advisory directs users to the Redmine security advisories page for detailed information on obtaining and applying the fixes.

What to do next

  1. Review Redmine version and identify if affected by vulnerabilities listed in CERTFR-2026-AVI-0306.
  2. Consult Redmine security advisories for available patches.
  3. Apply necessary patches to affected Redmine installations.

Source document (simplified)

Premier Ministre S.G.D.S.N

Agence nationale
de la sécurité des
systèmes d'information

Paris, le 17 mars 2026 N° CERTFR-2026-AVI-0306 Affaire suivie par: CERT-FR

Avis du CERT-FR

Objet: Multiples vulnérabilités dans Redmine

Gestion du document

| Référence | CERTFR-2026-AVI-0306 |
| Titre | Multiples vulnérabilités dans Redmine |
| Date de la première version | 17 mars 2026 |
| Date de la dernière version | 17 mars 2026 |
| Source(s) | Bulletin de sécurité Redmine security_advisories du 17 mars 2026 |
Une gestion de version détaillée se trouve à la fin de ce document.


Risques

  • Contournement de la politique de sécurité
  • Injection de code indirecte à distance (XSS)
  • Non spécifié par l'éditeur

Systèmes affectés

  • Redmine versions 6.0.x antérieures à 6.0.9
  • Redmine versions 6.1.x antérieures à 6.1.2
  • Redmine versions antérieures à 5.1.12

Résumé

De multiples vulnérabilités ont été découvertes dans Redmine. Elles permettent à un attaquant de provoquer une injection de code indirecte à distance (XSS), un contournement de la politique de sécurité et un problème de sécurité non spécifié par l'éditeur.

Solutions

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

Documentation


Gestion détaillée du document

  1. le 17 mars 2026 Version initiale

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
CERT-FR
Published
March 17th, 2026
Instrument
Notice
Legal weight
Non-binding
Stage
Final
Change scope
Substantive

Who this affects

Applies to
Technology companies
Geographic scope
National (France)

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Topics
Software Vulnerabilities XSS

Get Data Privacy & Cybersecurity alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when CERT-FR Security Advisories publishes new changes.

Free. Unsubscribe anytime.