Vulnerability record · CVE-2011-4929 · published 8 October 2012
CVE-2011-4929: Redmine bazaar repository adapter allows remote command execution
Redmine · Redmine
Redmine 0.9.x and 1.0.x before 1.0.5 contain an unspecified vulnerability in the bazaar repository adapter that lets remote attackers execute arbitrary commands. The flaw is reachable over the network without authentication, so any exposed Redmine instance running an affected version is at risk. The description does not identify the exact vectors or code path involved.
Description
Unspecified vulnerability in the bazaar repository adapter in Redmine 0.9.x and 1.0.x before 1.0.5 allows remote attackers to execute arbitrary commands via unknown vectors.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote unauthenticated command execution with a high EPSS score, though the exact vector is unspecified and no KEV listing exists.
What it is
Redmine 0.9.x and 1.0.x before 1.0.5 contain an unspecified vulnerability in the bazaar repository adapter that lets remote attackers execute arbitrary commands. The flaw is reachable over the network without authentication, so any exposed Redmine instance running an affected version is at risk. The description does not identify the exact vectors or code path involved.
Impact
An attacker can run arbitrary commands on the Redmine host, which typically means full compromise of the application server and any data or credentials it can reach. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as partial.
Attack surface
The CVSS 2.0 vector AV:N/AC:L/Au:N indicates the flaw is reachable over the network with no authentication and low complexity. The record does not state whether user interaction is required or which request path triggers the adapter.
Exploitation
CVE-2011-4929 is not listed in CISA KEV and no ransomware use is documented, but EPSS gives a 30-day probability of 0.464 (98.8th percentile), indicating elevated predicted exploitation activity. Reference tags include only a Vendor Advisory, with no public exploit tag.
What to do
- Upgrade Redmine to 1.0.5 or later, or apply the vendor fix referenced in the Redmine advisory.
- If upgrade is not possible, disable or remove the bazaar repository adapter and any bazaar-backed repositories.
- Restrict network access to the Redmine web interface to trusted users and networks.
- Apply the Debian security update DSA-2261 if Redmine is installed from Debian packages.
- Review Redmine repository configuration for untrusted or unnecessary SCM adapters.
Detection
- Search Redmine and web server logs for requests to repository or bazaar-related endpoints from unexpected source IPs.
- Monitor for child processes spawned by the Redmine application user, especially shell or bzr commands.
- Audit Redmine repository settings for enabled bazaar adapters and unexpected repository paths.
- Check for outbound connections or file changes originating from the Redmine host after repository-related requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-4929 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-4929), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.