SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-24896

Malicious users could use this vulnerability to retrieve the name of a tracker they cannot access as well as the name of the fields used in reports.

MEDIUM 4.3EPSS 0.76%

Does this matter?

Lower severity and a low EPSS score (0.76%). Track it; it rarely justifies an emergency change on its own.

Description

Tuleap is a Free & Open Source Suite to manage software developments and collaboration. In versions prior to 13.7.99.239 Tuleap does not properly verify authorizations when displaying the content of tracker report renderer and chart widgets. Malicious users could use this vulnerability to retrieve the name of a tracker they cannot access as well as the name of the fields used in reports.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
0.76% probability · 53th percentile
CISA KEV
Not listed
Weakness
CWE-862
Affected
enalean/tuleap
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.