CVE-2024-23344

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Some users might get access to restricted information when a process validates the permissions of multiple users (e.g. mail notifications). This issue has been patched in version 15.4.99.140 of Tuleap Community Edition.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:*

History

15 Feb 2024, 14:23

Type Values Removed Values Added
CPE cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:*
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 6.5
References () https://github.com/Enalean/tuleap/commit/0329e21d268510bc00fed707406103edabf10e42 - () https://github.com/Enalean/tuleap/commit/0329e21d268510bc00fed707406103edabf10e42 - Patch
References () https://github.com/Enalean/tuleap/security/advisories/GHSA-m3v5-2j5q-x85w - () https://github.com/Enalean/tuleap/security/advisories/GHSA-m3v5-2j5q-x85w - Patch, Vendor Advisory
References () https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=0329e21d268510bc00fed707406103edabf10e42 - () https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=0329e21d268510bc00fed707406103edabf10e42 - Patch
References () https://tuleap.net/plugins/tracker/?aid=35862 - () https://tuleap.net/plugins/tracker/?aid=35862 - Vendor Advisory
First Time Enalean tuleap
Enalean
Summary
  • (es) Tuleap es una suite de código abierto para mejorar la gestión de los desarrollos de software y la colaboración. Algunos usuarios pueden obtener acceso a información restringida cuando un proceso valida los permisos de múltiples usuarios (por ejemplo, notificaciones por correo). Este problema se solucionó en la versión 15.4.99.140 de Tuleap Community Edition.

06 Feb 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-06 16:15

Updated : 2024-02-15 14:23


NVD link : CVE-2024-23344

Mitre link : CVE-2024-23344

CVE.ORG link : CVE-2024-23344


JSON object : View

Products Affected

enalean

  • tuleap
CWE
NVD-CWE-noinfo CWE-200

Exposure of Sensitive Information to an Unauthorized Actor