Enalean

Tuleap

71 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 04.03.2025 17:15:19
  • Zuletzt bearbeitet 22.08.2025 15:37:24

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap is missing CSRF protections on tracker fields administrative operations. An attacker could use this vulnerability to trick victims into removing o...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 04.03.2025 17:15:19
  • Zuletzt bearbeitet 22.08.2025 16:00:59

Tuleap is an Open Source Suite to improve management of software developments and collaboration. In a standard usages of Tuleap, the issue has a limited impact, it will mostly leave dangling data. However, a malicious user could create and delete rep...

  • EPSS 0.23%
  • Veröffentlicht 04.03.2025 17:15:18
  • Zuletzt bearbeitet 22.08.2025 15:57:26

Tuleap is an Open Source Suite to improve management of software developments and collaboration. The mass emailing features do not sanitize the content of the HTML emails. A malicious user could use this issue to facilitate a phishing attempt or to i...

  • EPSS 0.12%
  • Veröffentlicht 04.03.2025 17:15:18
  • Zuletzt bearbeitet 22.08.2025 15:53:42

Tuleap is an Open Source Suite to improve management of software developments and collaboration. The password to connect the Redis instance is not purged from the archive generated with tuleap collect-system-data. These archives are likely to be used...

  • EPSS 0.2%
  • Veröffentlicht 03.03.2025 16:15:43
  • Zuletzt bearbeitet 10.07.2025 16:59:17

Tuleap is an open-source suite designed to improve software development management and collaboration. A malicious user with access to a tracker could force-reset certain field configurations, leading to potential information loss. The display time at...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 03.03.2025 16:15:43
  • Zuletzt bearbeitet 10.07.2025 16:48:42

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap allows cross-site scripting (XSS) via the tracker names used in the semantic timeframe deletion message. A tracker administrator with a semantic t...

  • EPSS 0.16%
  • Veröffentlicht 03.02.2025 22:15:28
  • Zuletzt bearbeitet 22.08.2025 15:59:15

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Users (possibly anonymous ones if the widget is used in the dashboard of a public project) might get access to artifacts they should not see. This issue ...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 03.02.2025 22:15:28
  • Zuletzt bearbeitet 22.08.2025 16:19:54

Tuleap is an Open Source Suite to improve management of software developments and collaboration. In affected versions an unauthorized user might get access to restricted information. This issue has been addressed in Tuleap Community Edition 16.3.99.1...

Exploit
  • EPSS 0.12%
  • Veröffentlicht 09.12.2024 19:15:13
  • Zuletzt bearbeitet 22.08.2025 16:19:06

Tuleap is an open source suite to improve management of software developments and collaboration. In Tuleap Community Edition prior to version 16.1.99.50 and Tuleap Enterprise Edition prior to versions 16.1-4 and 16.0-7, a malicious user with the abil...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 14.10.2024 18:15:04
  • Zuletzt bearbeitet 17.10.2024 13:50:45

Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.113, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 15.12-5, users might see tracker names they should n...