Tuleap is a Free & Open Source Suite to manage software developments and collaboration. In versions prior to 13.7.99.239 Tuleap does not properly verify authorizations when displaying the content of tracker report renderer and chart widgets. Malicious users could use this vulnerability to retrieve the name of a tracker they cannot access as well as the name of the fields used in reports.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2022-06-06T19:30:15

Updated: 2024-08-03T04:29:00.821Z

Reserved: 2022-02-10T00:00:00

Link: CVE-2022-24896

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-06-09T06:15:07.053

Modified: 2022-06-15T17:42:52.937

Link: CVE-2022-24896

cve-icon Redhat

No data.