Описание
Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.37, Tuleap Enterprise Edition 15.13-3, and Tuleap Enterprise Edition 15.12-6, a site administrator could create an artifact link type with a forward label allowing them to execute uncontrolled code (or at least achieve content injection) in a mail client. Tuleap Community Edition 15.13.99.37, Tuleap Enterprise Edition 15.13-3, and Tuleap Enterprise Edition 15.12-6 fix this issue.
Ссылки
- Patch
- Third Party Advisory
- Issue TrackingPatch
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 15.12-6 (исключая)Версия до 15.13.99.37 (исключая)Версия от 15.13-0 (включая) до 15.13-3 (исключая)
Одно из
cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*
EPSS
Процентиль: 33%
0.00134
Низкий
4.8 Medium
CVSS3
4.8 Medium
CVSS3
Дефекты
CWE-79
EPSS
Процентиль: 33%
0.00134
Низкий
4.8 Medium
CVSS3
4.8 Medium
CVSS3
Дефекты
CWE-79