CVE-2024-46980
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Published Oct 14, 2024
Updated: Oct 16, 2024
CWE ID 79
Summary
CVE-2024-46980 is a vulnerability affecting Tuleap, a tool for managing application and system development. Prior to versions 15.13.99.37, 15.13-3, and 15.12-6 of Tuleap Community and Enterprise Editions, a site administrator could create a maliciously crafted artifact link type with a forward label, allowing them to execute uncontrolled code or perform content injection in a mail client. This issue has been resolved in the mentioned versions.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Enalean Tuleap
Affected Vendors
- Enalean