Tuleap is an Open Source Suite to improve management of software developments and collaboration. Users (possibly anonymous ones if the widget is used in the dashboard of a public project) might get access to artifacts they should not see. This issue has been addressed in Tuleap Community Edition 16.3.99.1737562605 as well as Tuleap Enterprise Edition 16.3-5 and Tuleap Enterprise Edition 16.2-7. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Metrics
Affected Vendors & Products
References
History
Tue, 04 Feb 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 03 Feb 2025 21:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Users (possibly anonymous ones if the widget is used in the dashboard of a public project) might get access to artifacts they should not see. This issue has been addressed in Tuleap Community Edition 16.3.99.1737562605 as well as Tuleap Enterprise Edition 16.3-5 and Tuleap Enterprise Edition 16.2-7. Users are advised to upgrade. There are no known workarounds for this vulnerability. | |
Title | Artifact permissions are not verified in the Cross Tracker Search widget in Tuleap | |
Weaknesses | CWE-280 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-04T18:47:14.573Z
Reserved: 2025-01-16T17:31:06.460Z
Link: CVE-2025-24029

Updated: 2025-02-04T18:47:09.919Z

Status : Received
Published: 2025-02-03T22:15:28.320
Modified: 2025-02-03T22:15:28.320
Link: CVE-2025-24029

No data.