Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.110, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 15.12-5, administrators of a project can access the content of trackers with permissions restrictions of project they are members of but not admin via the cross tracker search widget. Tuleap Community Edition 15.13.99.110, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 15.12-8 fix this issue.
History

Thu, 17 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Enalean
Enalean tuleap
Weaknesses CWE-755
CPEs cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*
Vendors & Products Enalean
Enalean tuleap

Tue, 15 Oct 2024 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Oct 2024 18:15:00 +0000

Type Values Removed Values Added
Description Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.110, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 15.12-5, administrators of a project can access the content of trackers with permissions restrictions of project they are members of but not admin via the cross tracker search widget. Tuleap Community Edition 15.13.99.110, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 15.12-8 fix this issue.
Title Permissions are incorrectly verified for project administrators in the cross tracker search widget
Weaknesses CWE-280
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-10-14T17:53:55.763Z

Updated: 2024-10-15T15:37:35.456Z

Reserved: 2024-09-30T21:28:53.231Z

Link: CVE-2024-47766

cve-icon Vulnrichment

Updated: 2024-10-15T15:37:31.629Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-14T18:15:04.387

Modified: 2024-10-17T13:48:40.240

Link: CVE-2024-47766

cve-icon Redhat

No data.