Tuleap is a Free & Open Source Suite to manage software developments and collaboration. In versions prior to 13.7.99.239 Tuleap does not properly verify authorizations when displaying the content of tracker report renderer and chart widgets. Malicious users could use this vulnerability to retrieve the name of a tracker they cannot access as well as the name of the fields used in reports.
References
Link | Resource |
---|---|
https://github.com/Enalean/tuleap/commit/8e99e7c82d9fe569799019b9e1d614d38a184313 | Patch Third Party Advisory |
https://github.com/Enalean/tuleap/security/advisories/GHSA-x962-x43g-qw39 | Patch Third Party Advisory |
https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=8e99e7c82d9fe569799019b9e1d614d38a184313 | Patch Vendor Advisory |
https://tuleap.net/plugins/tracker/?aid=26729 | Issue Tracking Vendor Advisory |
https://github.com/Enalean/tuleap/commit/8e99e7c82d9fe569799019b9e1d614d38a184313 | Patch Third Party Advisory |
https://github.com/Enalean/tuleap/security/advisories/GHSA-x962-x43g-qw39 | Patch Third Party Advisory |
https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=8e99e7c82d9fe569799019b9e1d614d38a184313 | Patch Vendor Advisory |
https://tuleap.net/plugins/tracker/?aid=26729 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 06:51
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/Enalean/tuleap/commit/8e99e7c82d9fe569799019b9e1d614d38a184313 - Patch, Third Party Advisory | |
References | () https://github.com/Enalean/tuleap/security/advisories/GHSA-x962-x43g-qw39 - Patch, Third Party Advisory | |
References | () https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=8e99e7c82d9fe569799019b9e1d614d38a184313 - Patch, Vendor Advisory | |
References | () https://tuleap.net/plugins/tracker/?aid=26729 - Issue Tracking, Vendor Advisory |
Information
Published : 2022-06-09 06:15
Updated : 2024-11-21 06:51
NVD link : CVE-2022-24896
Mitre link : CVE-2022-24896
CVE.ORG link : CVE-2022-24896
JSON object : View
Products Affected
enalean
- tuleap
CWE
CWE-862
Missing Authorization