Tuleap is a Free & Open Source Suite to manage software developments and collaboration. In versions prior to 13.7.99.239 Tuleap does not properly verify authorizations when displaying the content of tracker report renderer and chart widgets. Malicious users could use this vulnerability to retrieve the name of a tracker they cannot access as well as the name of the fields used in reports.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/Enalean/tuleap/commit/8e99e7c82d9fe569799019b9e1d614d38a184313 | Patch Third Party Advisory | 
| https://github.com/Enalean/tuleap/security/advisories/GHSA-x962-x43g-qw39 | Patch Third Party Advisory | 
| https://tuleap.net/plugins/tracker/?aid=26729 | Issue Tracking Vendor Advisory | 
| https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=8e99e7c82d9fe569799019b9e1d614d38a184313 | Patch Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
Information
                Published : 2022-06-08 23:15
Updated : 2022-06-15 10:42
NVD link : CVE-2022-24896
Mitre link : CVE-2022-24896
JSON object : View
CWE
                
                    
                        
                        CWE-862
                        
            Missing Authorization
Products Affected
                enalean
- tuleap


