CVE-2022-24896

MEDIUM

Tuleap < 13.7.99.239 - Missing Authorization in Tracker Report Renderer and Chart Widgets

Title source: llm
STIX 2.1

Description

Tuleap is a Free & Open Source Suite to manage software developments and collaboration. In versions prior to 13.7.99.239 Tuleap does not properly verify authorizations when displaying the content of tracker report renderer and chart widgets. Malicious users could use this vulnerability to retrieve the name of a tracker they cannot access as well as the name of the fields used in reports.

References (4)

Core 4

Scores

CVSS v3 4.3
EPSS 0.0071
EPSS Percentile 48.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (2)
enalean/tuleap < 13.6-5
enalean/tuleap < 13.7.99.239
Published Jun 09, 2022
Tracked Since Feb 18, 2026