6.5
CVE-2024-23344
- EPSS 0.53%
- Veröffentlicht 06.02.2024 16:15:52
- Zuletzt bearbeitet 21.11.2024 08:57:33
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
Tuleap's content of artifacts might be readable by unauthorized users
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Some users might get access to restricted information when a process validates the permissions of multiple users (e.g. mail notifications). This issue has been patched in version 15.4.99.140 of Tuleap Community Edition.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.53% | 0.405 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| security-advisories@github.com | 5.3 | 1.6 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
https://github.com/Enalean/tuleap/commit/0329e21d268510bc00fed707406103edabf10e42
https://github.com/Enalean/tuleap/security/advisories/GHSA-m3v5-2j5q-x85w
https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=0329e21d268510bc00fed707406103edabf10e42
https://tuleap.net/plugins/tracker/?aid=35862