CVE-2024-30246

HIGH

Tuleap - Info Disclosure

Title source: llm
STIX 2.1

Description

Tuleap is an Open Source Suite to improve management of software developments and collaboration. A malicious user could exploit this issue on purpose to delete information on the instance or possibly gain access to restricted artifacts. It is however not possible to control exactly which information is deleted. Information from theDate, File, Float, Int, List, OpenList, Text, and Permissions on artifact (this one can lead to the disclosure of restricted information) fields can be impacted. This vulnerability is fixed in Tuleap Community Edition version 15.7.99.6 and Tuleap Enterprise Edition 15.7-2, 15.6-5, 15.5-6, 15.4-8, 15.3-6, 15.2-5, 15.1-9, 15.0-9, and 14.12-6.

Scores

CVSS v3 7.6
EPSS 0.0009
EPSS Percentile 24.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-440 CWE-670
Status published
Products (3)
enalean/tuleap 15.7-1
enalean/tuleap 14.11.99.34 - 15.7.99.6
enalean/tuleap 14.12-1 - 14.12-6
Published Mar 29, 2024
Tracked Since Feb 18, 2026