CVE-2024-46980

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Oct 14, 2024
Updated: Oct 16, 2024
CWE ID 79

Summary

CVE-2024-46980 is a vulnerability affecting Tuleap, a tool for managing application and system development. Prior to versions 15.13.99.37, 15.13-3, and 15.12-6 of Tuleap Community and Enterprise Editions, a site administrator could create a maliciously crafted artifact link type with a forward label, allowing them to execute uncontrolled code or perform content injection in a mail client. This issue has been resolved in the mentioned versions.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share