CVE-2024-23344
Last modified
CVE-2024-23344 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Tuleap is an Open Source Suite to improve management of software developments and collaboration. Some users might get access to restricted information when a process validates the permissions of multiple users (e.g. EPSS estimates a 0.53% chance of exploitation in the next 30 days.
Description
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Some users might get access to restricted information when a process validates the permissions of multiple users (e.g. mail notifications). This issue has been patched in version 15.4.99.140 of Tuleap Community Edition.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Enalean | Tuleap | < 15.3.5 |
| Enalean | Tuleap | >= 15.2.99.49, < 15.4.99.140 |
References
- https://github.com/Enalean/tuleap/security/advisories/GHSA-m3v5-2j5q-x85wPatch, Vendor Advisory
- https://tuleap.net/plugins/tracker/?aid=35862Vendor Advisory
- https://github.com/Enalean/tuleap/security/advisories/GHSA-m3v5-2j5q-x85wPatch, Vendor Advisory
- https://tuleap.net/plugins/tracker/?aid=35862Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-23344?
How severe is CVE-2024-23344?
How do I fix CVE-2024-23344?
Are you affected by CVE-2024-23344?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
