Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.110, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 15.12-5, administrators of a project can access the content of trackers with permissions restrictions of project they are members of but not admin via the cross tracker search widget. Tuleap Community Edition 15.13.99.110, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 15.12-8 fix this issue.
Metrics
Affected Vendors & Products
References
History
Thu, 17 Oct 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Enalean
Enalean tuleap |
|
Weaknesses | CWE-755 | |
CPEs | cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:* cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:* |
|
Vendors & Products |
Enalean
Enalean tuleap |
Tue, 15 Oct 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 14 Oct 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.110, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 15.12-5, administrators of a project can access the content of trackers with permissions restrictions of project they are members of but not admin via the cross tracker search widget. Tuleap Community Edition 15.13.99.110, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 15.12-8 fix this issue. | |
Title | Permissions are incorrectly verified for project administrators in the cross tracker search widget | |
Weaknesses | CWE-280 | |
References |
|
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-10-14T17:53:55.763Z
Updated: 2024-10-15T15:37:35.456Z
Reserved: 2024-09-30T21:28:53.231Z
Link: CVE-2024-47766
Vulnrichment
Updated: 2024-10-15T15:37:31.629Z
NVD
Status : Analyzed
Published: 2024-10-14T18:15:04.387
Modified: 2024-10-17T13:48:40.240
Link: CVE-2024-47766
Redhat
No data.