Tuleap Suite Vulnerability Could Lead to Information Disclosure
CVE-2024-30246

7.1HIGH

Key Information:

Vendor

Enalean

Status
Vendor
CVE Published:
29 March 2024

What is CVE-2024-30246?

A vulnerability in Tuleap, an Open Source Suite for software development management, poses a risk where a malicious user can delete instance information or gain unauthorized access to restricted artifacts. This exploitation can affect various fields such as Date, File, Float, Int, List, OpenList, Text, and Permissions, leading to potential loss of sensitive data. The ability to control which specific information is deleted is limited. It is critical for users of affected Tuleap versions to apply the necessary updates to mitigate these risks.

Affected Version(s)

tuleap >= 14.11.99.34, < 15.7.99.6

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.