Description
Tuleap is an Open Source Suite to improve management of software developments and collaboration. In affected versions an unauthorized user might get access to restricted information. This issue has been addressed in Tuleap Community Edition 16.3.99.1736242932, Tuleap Enterprise Edition 16.2-5, and Tuleap Enterprise Edition 16.3-2. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Problem types
CWE-280: Improper Handling of Insufficient Permissions or Privileges
Product status
References
tuleap.net/plugins/tracker/?aid=41434
github.com/...tuleap/security/advisories/GHSA-f34g-wc2m-mf76
tuleap.net/...mit&h=3edf8158ba40be66f0b661888b8b2805784795d1
tuleap.net/plugins/tracker/?aid=41434