CVE-2024-37167

MEDIUM

Tuleap < 15.8-5 and < 15.9.99.97 - Improper Authorization

Title source: llm
STIX 2.1

Description

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Users are able to see backlog items that they should not see. This issue has been patched in Tuleap Community Edition version 15.9.99.97.

Scores

CVSS v3 4.3
EPSS 0.0035
EPSS Percentile 27.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-285
Status published
Products (2)
enalean/tuleap < 15.8-5
enalean/tuleap < 15.9.99.97
Published Jun 25, 2024
Tracked Since Feb 18, 2026