Tuleap is a Free & Open Source Suite to manage software developments and collaboration. In versions prior to 13.7.99.239 Tuleap does not properly verify authorizations when displaying the content of tracker report renderer and chart widgets. Malicious users could use this vulnerability to retrieve the name of a tracker they cannot access as well as the name of the fields used in reports.
References
Link | Resource |
---|---|
https://github.com/Enalean/tuleap/commit/8e99e7c82d9fe569799019b9e1d614d38a184313 | Patch Third Party Advisory |
https://github.com/Enalean/tuleap/security/advisories/GHSA-x962-x43g-qw39 | Patch Third Party Advisory |
https://tuleap.net/plugins/tracker/?aid=26729 | Issue Tracking Vendor Advisory |
https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=8e99e7c82d9fe569799019b9e1d614d38a184313 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-06-08 23:15
Updated : 2022-06-15 10:42
NVD link : CVE-2022-24896
Mitre link : CVE-2022-24896
JSON object : View
CWE
CWE-862
Missing Authorization
Products Affected
enalean
- tuleap