CVE-2018-17298: Critical severity enalean tuleap vulnerability
Published Sep 21, 2018
·Updated
An issue was discovered in Enalean Tuleap before 10.5. Reset password links are not invalidated after a user changes its password.
Affected Software
1 affected component
Enalean Tuleap<10.5
Remediation
Patch Available
Event History
Sep 21, 2018
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue in Enalean Tuleap?
The vulnerability ID is CVE-2018-17298.
2
What is the severity level of CVE-2018-17298?
The severity level of CVE-2018-17298 is critical.
3
What is the description of CVE-2018-17298?
CVE-2018-17298 is a vulnerability in Enalean Tuleap where reset password links are not invalidated after a user changes its password.
4
Which version of Enalean Tuleap is affected by CVE-2018-17298?
Enalean Tuleap versions up to exclusive 10.5 are affected by CVE-2018-17298.
5
Is there a fix available for CVE-2018-17298?
Yes, there are fixes available for CVE-2018-17298. More information can be found in the references provided.