Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.110, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 15.12-5, administrators of a project can access the content of trackers with permissions restrictions of project they are members of but not admin via the cross tracker search widget. Tuleap Community Edition 15.13.99.110, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 15.12-8 fix this issue.
References
Link | Resource |
---|---|
https://github.com/Enalean/tuleap/security/advisories/GHSA-qfrh-fv84-93hx | Exploit Patch Third Party Advisory |
https://github.com/Enalean/tuleap/commit/529d11b70796589767dd27a40ebadf3eaf8f5674 | Patch |
https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=529d11b70796589767dd27a40ebadf3eaf8f5674 | Issue Tracking Patch |
https://tuleap.net/plugins/tracker/?aid=39736 | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
17 Oct 2024, 13:48
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-755 | |
CPE | cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:* cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:* |
|
First Time |
Enalean
Enalean tuleap |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.9 |
References | () https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=529d11b70796589767dd27a40ebadf3eaf8f5674 - Issue Tracking, Patch | |
References | () https://github.com/Enalean/tuleap/security/advisories/GHSA-qfrh-fv84-93hx - Exploit, Patch, Third Party Advisory | |
References | () https://github.com/Enalean/tuleap/commit/529d11b70796589767dd27a40ebadf3eaf8f5674 - Patch | |
References | () https://tuleap.net/plugins/tracker/?aid=39736 - Exploit, Third Party Advisory |
14 Oct 2024, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-10-14 18:15
Updated : 2024-10-17 13:48
NVD link : CVE-2024-47766
Mitre link : CVE-2024-47766
JSON object : View
Products Affected
enalean
- tuleap
CWE
CWE-755
Improper Handling of Exceptional Conditions