Tuleap is an Open Source Suite to improve management of software developments and collaboration. In versions prior to 14.2.99.104, project level authorizations are not properly verified when accessing the project "homepage"/dashboards. Users not authorized to access a project may still be able to get some information provided by the widgets (e.g. number of members, content of the Notes widget...). This issue has been patched in Tuleap Community Edition 14.2.99.104, Tuleap Enterprise Edition 14.2-4, and Tuleap Enterprise Edition 14.1-5.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2022-12-13T06:40:05.477Z

Updated: 2024-08-03T14:24:03.397Z

Reserved: 2022-11-28T17:27:19.997Z

Link: CVE-2022-46160

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-12-13T07:15:13.980

Modified: 2022-12-15T19:59:48.823

Link: CVE-2022-46160

cve-icon Redhat

No data.