Описание
Tuleap is a Free & Open Source Suite to manage software developments and collaboration. In versions prior to 13.7.99.239 Tuleap does not properly verify authorizations when displaying the content of tracker report renderer and chart widgets. Malicious users could use this vulnerability to retrieve the name of a tracker they cannot access as well as the name of the fields used in reports.
Ссылки
- PatchThird Party Advisory
- PatchThird Party Advisory
- PatchVendor Advisory
- Issue TrackingVendor Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- PatchVendor Advisory
- Issue TrackingVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 13.6-5 (исключая)Версия до 13.7.99.239 (исключая)Версия от 13.7-1 (включая) до 13.7-4 (исключая)
Одно из
cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*
EPSS
Процентиль: 37%
0.00157
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-862
EPSS
Процентиль: 37%
0.00157
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-862