Description
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Users are able to see backlog items that they should not see. This issue has been patched in Tuleap Community Edition version 15.9.99.97.
References (4)
Core 4
Core References
Vendor Advisory x_refsource_confirm
https://github.com/Enalean/tuleap/security/advisories/GHSA-4c9f-284j-phvj
Patch x_refsource_misc
https://github.com/Enalean/tuleap/commit/13eec93a353d2daf47bb8b9c548cc02f78b93a5e
Broken Link x_refsource_misc
https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=13eec93a353d2daf47bb8b9c548cc02f78b93a5e
Vendor Advisory x_refsource_misc
https://tuleap.net/plugins/tracker/?aid=38297
Scores
CVSS v3
4.3
EPSS
0.0027
EPSS Percentile
50.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-285
Status
published
Products (2)
enalean/tuleap
< 15.8-5
enalean/tuleap
< 15.9.99.97
Published
Jun 25, 2024
Tracked Since
Feb 18, 2026