CVE-2024-25130

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
22/02/2024
Last modified:
05/02/2025

Description

Tuleap is an open source suite to improve management of software developments and collaboration. Prior to version 15.5.99.76 of Tuleap Community Edition and prior to versions 15.5-4 and 15.4-7 of Tuleap Enterprise Edition, users with a read access to a tracker where the mass update feature is used might get access to restricted information. Tuleap Community Edition 15.5.99.76, Tuleap Enterprise Edition 15.5-4, and Tuleap Enterprise Edition 15.4-7 contain a patch for this issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:* 15.4-7 (excluding)
cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:* 15.5.99.76 (excluding)
cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:* 15.5 (including) 15.5-4 (excluding)