Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-42171 | Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.40, Tuleap Enterprise Edition 15.13-3, and Tuleap Enterprise Edition 15.12-6, users might receive email notification with information they should not have access to. Tuleap Community Edition 15.13.99.40, Tuleap Enterprise Edition 15.13-3, and Tuleap Enterprise Edition 15.12-6 fix this issue. |
Wed, 16 Oct 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-755 | |
| CPEs | cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:* cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:* |
Tue, 15 Oct 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Enalean
Enalean tuleap Enalean tuleap Enterprise |
|
| CPEs | cpe:2.3:a:enalean:tuleap:*:*:*:*:*:*:*:* cpe:2.3:a:enalean:tuleap_enterprise:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Enalean
Enalean tuleap Enalean tuleap Enterprise |
|
| Metrics |
ssvc
|
Mon, 14 Oct 2024 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.40, Tuleap Enterprise Edition 15.13-3, and Tuleap Enterprise Edition 15.12-6, users might receive email notification with information they should not have access to. Tuleap Community Edition 15.13.99.40, Tuleap Enterprise Edition 15.13-3, and Tuleap Enterprise Edition 15.12-6 fix this issue. | |
| Title | Tuleap does not properly check permissions for email notifications in trackers | |
| Weaknesses | CWE-280 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-10-15T15:40:00.721Z
Reserved: 2024-09-16T16:10:09.019Z
Link: CVE-2024-46988
Updated: 2024-10-15T15:39:53.819Z
Status : Analyzed
Published: 2024-10-14T18:15:04.173
Modified: 2024-10-16T14:07:32.890
Link: CVE-2024-46988
No data.
OpenCVE Enrichment
No data.
EUVD