CVE-2014-7177: Medium severity enalean tuleap vulnerability
Published Oct 31, 2014
·Updated
XML External Entity vulnerability in Enalean Tuleap 7.2 and earlier allows remote authenticated users to read arbitrary files via a crafted xml document in a create action to plugins/tracker/.
Affected Software
1 affected component
Enalean Tuleap<=7.2
Event History
Oct 31, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-7177?
CVE-2014-7177 has a medium severity rating due to its ability to expose sensitive information through an XML External Entity injection.
2
How do I fix CVE-2014-7177?
To fix CVE-2014-7177, update Enalean Tuleap to version 7.3 or later, which includes fixes for this vulnerability.
3
Who is affected by CVE-2014-7177?
CVE-2014-7177 affects all Enalean Tuleap versions 7.2 and earlier.
4
What are the potential impacts of CVE-2014-7177?
CVE-2014-7177 can allow remote authenticated users to read arbitrary files on the server, leading to potential data exposure.
5
Is CVE-2014-7177 an authenticated vulnerability?
Yes, CVE-2014-7177 requires remote authenticated access to exploit the XML External Entity vulnerability.