Tuleap is a Free & Open Source Suite to manage software developments and collaboration. In versions prior to 13.7.99.239 Tuleap does not properly verify authorizations when displaying the content of tracker report renderer and chart widgets. Malicious users could use this vulnerability to retrieve the name of a tracker they cannot access as well as the name of the fields used in reports.
History

Wed, 23 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2022-06-06T19:30:15.000Z

Updated: 2025-04-23T18:19:16.848Z

Reserved: 2022-02-10T00:00:00.000Z

Link: CVE-2022-24896

cve-icon Vulnrichment

Updated: 2024-08-03T04:29:00.821Z

cve-icon NVD

Status : Modified

Published: 2022-06-09T06:15:07.053

Modified: 2024-11-21T06:51:20.723

Link: CVE-2022-24896

cve-icon Redhat

No data.