CVE-2024-47766

CVSS 3.1 Score 4.9 of 10 (medium)

Details

Published Oct 14, 2024
Updated: Oct 17, 2024
CWE ID 755
CWE ID 280

Summary

CVE-2024-47766 is a vulnerability affecting Tuleap, a tool used for end-to-end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.110, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 15.12-5, administrators with membership but not admin permissions in a project could access the content of trackers with restricted permissions via the cross tracker search widget. This issue has been addressed in Tuleap Community Edition 15.13.99.110, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 15.12-8 through subsequent updates.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share