CVE-2024-47766

Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.110, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 15.12-5, administrators of a project can access the content of trackers with permissions restrictions of project they are members of but not admin via the cross tracker search widget. Tuleap Community Edition 15.13.99.110, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 15.12-8 fix this issue.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*

History

17 Oct 2024, 13:48

Type Values Removed Values Added
References () https://github.com/Enalean/tuleap/commit/529d11b70796589767dd27a40ebadf3eaf8f5674 - () https://github.com/Enalean/tuleap/commit/529d11b70796589767dd27a40ebadf3eaf8f5674 - Patch
References () https://github.com/Enalean/tuleap/security/advisories/GHSA-qfrh-fv84-93hx - () https://github.com/Enalean/tuleap/security/advisories/GHSA-qfrh-fv84-93hx - Exploit, Patch, Third Party Advisory
References () https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=529d11b70796589767dd27a40ebadf3eaf8f5674 - () https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=529d11b70796589767dd27a40ebadf3eaf8f5674 - Issue Tracking, Patch
References () https://tuleap.net/plugins/tracker/?aid=39736 - () https://tuleap.net/plugins/tracker/?aid=39736 - Exploit, Third Party Advisory
First Time Enalean tuleap
Enalean
CWE CWE-755
CPE cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:*

15 Oct 2024, 12:57

Type Values Removed Values Added
Summary
  • (es) Tuleap es una herramienta para la trazabilidad de extremo a extremo de los desarrollos de aplicaciones y sistemas. Antes de Tuleap Community Edition 15.13.99.110, Tuleap Enterprise Edition 15.13-5 y Tuleap Enterprise Edition 15.12-5, los administradores de un proyecto pueden acceder al contenido de los rastreadores con restricciones de permisos del proyecto del que son miembros pero no administradores a través del widget de búsqueda de rastreadores cruzados. Tuleap Community Edition 15.13.99.110, Tuleap Enterprise Edition 15.13-5 y Tuleap Enterprise Edition 15.12-8 solucionan este problema.

14 Oct 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-14 18:15

Updated : 2024-10-17 13:48


NVD link : CVE-2024-47766

Mitre link : CVE-2024-47766

CVE.ORG link : CVE-2024-47766


JSON object : View

Products Affected

enalean

  • tuleap
CWE
CWE-755

Improper Handling of Exceptional Conditions

CWE-280

Improper Handling of Insufficient Permissions or Privileges