Impact
An authorization bypass through a user‑controlled key allows an attacker to retrieve information belonging to other users in Tuleap Enterprise Edition without proper authorization. The vulnerability is a flaw in the handling of user‑supplied keys, resulting in a confidentiality compromise. An exploited instance would enable an attacker to read, modify, or delete project data and personal user information normally protected by access controls.
Affected Systems
The affected systems are Dassault Systèmes Tuleap Enterprise Edition versions 17.0 through 17.5.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, and the EPSS score of < 1 % indicates a low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. It is inferred that the attack vector requires an authenticated user who has permission to create or modify keys; the attacker would supply a crafted key that bypasses authorization checks and grants access to another user’s data. Once the bypass is achieved, the attacker can exfiltrate confidential information from the vulnerable instance.
OpenCVE Enrichment