Описание
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Users (possibly anonymous ones if the widget is used in the dashboard of a public project) might get access to artifacts they should not see. This issue has been addressed in Tuleap Community Edition 16.3.99.1737562605 as well as Tuleap Enterprise Edition 16.3-5 and Tuleap Enterprise Edition 16.2-7. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Ссылки
- PatchThird Party Advisory
- Permissions Required
- Permissions Required
- Issue TrackingPatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 16.2-7 (исключая)Версия до 16.3.99.1737562605 (исключая)Версия от 16.3 (включая) до 16.3-5 (исключая)
Одно из
cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*
EPSS
Процентиль: 37%
0.00158
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-280
EPSS
Процентиль: 37%
0.00158
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-280