CVE-2024-25130
Tuleap's mass update clears the permissions on artifact field
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Tuleap is an open source suite to improve management of software developments and collaboration. Prior to version 15.5.99.76 of Tuleap Community Edition and prior to versions 15.5-4 and 15.4-7 of Tuleap Enterprise Edition, users with a read access to a tracker where the mass update feature is used might get access to restricted information. Tuleap Community Edition 15.5.99.76, Tuleap Enterprise Edition 15.5-4, and Tuleap Enterprise Edition 15.4-7 contain a patch for this issue.
Tuleap es una suite de código abierto para mejorar la gestión de los desarrollos de software y la colaboración. Antes de la versión 15.5.99.76 de Tuleap Community Edition y antes de las versiones 15.5-4 y 15.4-7 de Tuleap Enterprise Edition, los usuarios con acceso de lectura a un rastreador donde se utiliza la función de actualización masiva podían obtener acceso a información restringida. Tuleap Community Edition 15.5.99.76, Tuleap Enterprise Edition 15.5-4 y Tuleap Enterprise Edition 15.4-7 contienen un parche para este problema.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-02-05 CVE Reserved
- 2024-02-22 CVE Published
- 2024-02-23 EPSS Updated
- 2024-08-27 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://github.com/Enalean/tuleap/commit/57978a32508f5c6d0365419b6eaeb368aee20667 | X_refsource_misc | |
https://github.com/Enalean/tuleap/security/advisories/GHSA-mq7f-m6mj-hjj5 | X_refsource_confirm | |
https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=57978a32508f5c6d0365419b6eaeb368aee20667 | X_refsource_misc | |
https://tuleap.net/plugins/tracker/?aid=36803 | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Enalean Search vendor "Enalean" | Tuleap Search vendor "Enalean" for product "Tuleap" | < 15.5.99.76 Search vendor "Enalean" for product "Tuleap" and version " < 15.5.99.76" | en |
Affected
| ||||||
Enalean Search vendor "Enalean" | Tuleap Search vendor "Enalean" for product "Tuleap" | 15.5 Search vendor "Enalean" for product "Tuleap" and version "15.5" | en |
Affected
| ||||||
Enalean Search vendor "Enalean" | Tuleap Search vendor "Enalean" for product "Tuleap" | < 15.4 Search vendor "Enalean" for product "Tuleap" and version " < 15.4" | en |
Affected
|