CVE-2024-47766
CVSS 3.1 Score 4.9 of 10 (medium)
Details
Summary
CVE-2024-47766 is a vulnerability affecting Tuleap, a tool used for end-to-end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.110, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 15.12-5, administrators with membership but not admin permissions in a project could access the content of trackers with restricted permissions via the cross tracker search widget. This issue has been addressed in Tuleap Community Edition 15.13.99.110, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 15.12-8 through subsequent updates.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Enalean Tuleap
Affected Vendors
- Enalean