CVE-2024-46988

CVSS 3.1 Score 5.7 of 10 (medium)

Details

Published Oct 14, 2024
Updated: Oct 16, 2024
CWE ID 755
CWE ID 280

Summary

CVE-2024-46988 is a vulnerability affecting Tuleap, a tool for managing application and system development. Prior to Tuleap Community Edition 15.13.99.40, Tuleap Enterprise Edition 15.13-3, and Tuleap Enterprise Edition 15.12-6, users could receive email notifications containing information that exceeded their access privileges. This issue has been resolved in the specified versions. Unauthorized access to sensitive information through email notifications posed a potential security risk. The vulnerability did not allow unauthenticated users to gain access to the system, but affected users with inappropriate email notification permissions. System administrators are advised to update their Tuleap installations to the latest patched versions to mitigate this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share