CVE-2024-25130
Tuleap is an open source suite to improve management of software developments and collaboration.
Does this matter?
Lower severity and a low EPSS score (0.50%). Track it; it rarely justifies an emergency change on its own.
Description
Tuleap is an open source suite to improve management of software developments and collaboration. Prior to version 15.5.99.76 of Tuleap Community Edition and prior to versions 15.5-4 and 15.4-7 of Tuleap Enterprise Edition, users with a read access to a tracker where the mass update feature is used might get access to restricted information. Tuleap Community Edition 15.5.99.76, Tuleap Enterprise Edition 15.5-4, and Tuleap Enterprise Edition 15.4-7 contain a patch for this issue.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.50% probability · 41th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- enalean/tuleap
- Source
- security-advisories@github.com
References
- https://github.com/Enalean/tuleap/commit/57978a32508f5c6d0365419b6eaeb368aee20667Patch
- https://github.com/Enalean/tuleap/security/advisories/GHSA-mq7f-m6mj-hjj5Patch, Vendor Advisory
- https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=57978a32508f5c6d0365419b6eaeb368aee20667Broken Link
- https://tuleap.net/plugins/tracker/?aid=36803Vendor Advisory
- https://github.com/Enalean/tuleap/commit/57978a32508f5c6d0365419b6eaeb368aee20667Patch
- https://github.com/Enalean/tuleap/security/advisories/GHSA-mq7f-m6mj-hjj5Patch, Vendor Advisory
- https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=57978a32508f5c6d0365419b6eaeb368aee20667Broken Link
- https://tuleap.net/plugins/tracker/?aid=36803Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.