Описание
Tuleap is an Open Source Suite to improve management of software developments and collaboration. The mass emailing features do not sanitize the content of the HTML emails. A malicious user could use this issue to facilitate a phishing attempt or to indirectly exploit issues in the recipients mail clients. This vulnerability is fixed in Tuleap Community Edition 16.4.99.1740567344 and Tuleap Enterprise Edition 16.4-6 and 16.3-11.
Ссылки
- Patch
- PatchThird Party Advisory
- Issue TrackingPatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 16.3-11 (исключая)Версия до 16.4.99.1740567344 (исключая)Версия от 16.4 (включая) до 16.4-6 (исключая)
Одно из
cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*
EPSS
Процентиль: 45%
0.00226
Низкий
4.1 Medium
CVSS3
5.4 Medium
CVSS3
Дефекты
CWE-79
EPSS
Процентиль: 45%
0.00226
Низкий
4.1 Medium
CVSS3
5.4 Medium
CVSS3
Дефекты
CWE-79