CVE-2024-37167

MEDIUM

Enalean Tuleap < 15.8-5 - Improper Authorization

Title source: rule
STIX 2.1

Description

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Users are able to see backlog items that they should not see. This issue has been patched in Tuleap Community Edition version 15.9.99.97.

Scores

CVSS v3 4.3
EPSS 0.0027
EPSS Percentile 50.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-285
Status published
Products (2)
enalean/tuleap < 15.8-5
enalean/tuleap < 15.9.99.97
Published Jun 25, 2024
Tracked Since Feb 18, 2026