Описание
Tuleap is an Open Source Suite to improve management of software developments and collaboration. In affected versions an unauthorized user might get access to restricted information. This issue has been addressed in Tuleap Community Edition 16.3.99.1736242932, Tuleap Enterprise Edition 16.2-5, and Tuleap Enterprise Edition 16.3-2. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Ссылки
- PatchThird Party Advisory
- Permissions Required
- ExploitIssue TrackingPatchVendor Advisory
- ExploitIssue TrackingPatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 16.2-5 (исключая)Версия до 16.3.99.1736242932 (исключая)Версия от 16.3 (включая) до 16.3-2 (исключая)
Одно из
cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*
EPSS
Процентиль: 30%
0.0011
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-280
EPSS
Процентиль: 30%
0.0011
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-280