CVE-2024-47766
Tuleap is a tool for end to end traceability of application and system developments.
Does this matter?
Lower severity and a low EPSS score (0.51%). Track it; it rarely justifies an emergency change on its own.
Description
Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.110, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 15.12-5, administrators of a project can access the content of trackers with permissions restrictions of project they are members of but not admin via the cross tracker search widget. Tuleap Community Edition 15.13.99.110, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 15.12-8 fix this issue.
- CVSS 3.1
- 4.9 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.51% probability · 42th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-280, CWE-755
- Affected
- enalean/tuleap
- Source
- security-advisories@github.com
References
- https://github.com/Enalean/tuleap/commit/529d11b70796589767dd27a40ebadf3eaf8f5674Patch
- https://github.com/Enalean/tuleap/security/advisories/GHSA-qfrh-fv84-93hxExploit, Patch, Third Party Advisory
- https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=529d11b70796589767dd27a40ebadf3eaf8f5674Issue Tracking, Patch
- https://tuleap.net/plugins/tracker/?aid=39736Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.