Tuleap is a Free & Open Source Suite to manage software developments and collaboration. In versions prior to 13.7.99.239 Tuleap does not properly verify authorizations when displaying the content of tracker report renderer and chart widgets. Malicious users could use this vulnerability to retrieve the name of a tracker they cannot access as well as the name of the fields used in reports.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2022-06-06T19:30:15
Updated: 2024-08-03T04:29:00.821Z
Reserved: 2022-02-10T00:00:00
Link: CVE-2022-24896
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-06-09T06:15:07.053
Modified: 2024-11-21T06:51:20.723
Link: CVE-2022-24896
Redhat
No data.