Redmine 7.0.2 and 6.1.5 released
New maintenance releases for the Redmine 7.0 and 6.1 series are now available to Download, addressing security vulnerabilities along with various bug fixes and performance improvements.
Security FixesBoth versions (7.0.2 and 6.1.5) include:
- Defect #44467: Private/invisible issue subjects leaked via REST API
include=children - Defect #44468: Private project names and role assignments leaked via
GET /groups/<id>.json?include=memberships - Defect #44429: DOM-Based XSS via Clipboard HTML Paste
- Rails Support: Rails updated to 8.1.4 (7.0.2) and 7.2.4 (6.1.5).
- Webhooks: Added an administration page listing all webhooks (#44337) and fixed N+1 queries (#44386).
- Performance: Optimized SVG icon rendering with path caching (#44415, #44412) and fixed UI freezes on custom fields with thousands of values (#44372).
- UI & Responsive: Refreshed mobile header and flyout menu colors (#44444) and fixed autocomplete popup positioning (#44408).
- Attachments & SCM: Fixed Ghostscript timeout process leaks (#44378), SVN URLs containing spaces (#27043), and Git branches containing 40-character hex strings (#44476).
Download and Changelog: Find the new packages in the Download section, see the full list of changes in the Changelog and the updated Security Advisories.
Many thanks to all contributors and security researchers who helped with these releases.
Comments