Tracker report renderer and chart widgets leak information in Tuleap
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 4.3epss 0.8%
exploitation probability
0.8%top 47% of all CVEs
observed exploitation
nono source reports it
Tuleap is a Free & Open Source Suite to manage software developments and collaboration. In versions prior to 13.7.99.239 Tuleap does not properly verify authorizations when displaying the content of tracker report renderer and chart widgets. Malicious users could use this vulnerability to retrieve the name of a tracker they cannot access as well as the name of the fields used in reports.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected products
Enalean · tuleapReferences
https://github.com/Enalean/tuleap/commit/8e99e7c82d9fe569799019b9e1d614d38a184313https://github.com/Enalean/tuleap/security/advisories/GHSA-x962-x43g-qw39https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=8e99e7c82d9fe569799019b9e1d614d38a184313https://tuleap.net/plugins/tracker/?aid=26729