CVE-2023-30619: XSS in the tooltip via an artifact title
Tuleap Open ALM is a Libre and Open Source tool for end to end traceability of application and system developments. The title of an artifact is not properly escaped in the tooltip. A malicious user with the capability to create an artifact or to edit a field title could force victim to execute uncontrolled code. This issue has been patched in version 14.7.99.143.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-30619?
CVE-2023-30619 is a vulnerability in Tuleap Open ALM, an open-source tool for traceability of application and system developments.
What is the severity of CVE-2023-30619?
The severity of CVE-2023-30619 is medium, with a CVSS score of 5.4.
How can a malicious user exploit this vulnerability in Tuleap Open ALM?
A malicious user with the capability to create an artifact or edit a field title can force a victim to execute unintended actions.
Which versions of Tuleap Open ALM are affected by CVE-2023-30619?
Versions 14.7.99.76 to 14.7.99.143 of Tuleap Open ALM are affected by CVE-2023-30619.
Is there a fix for CVE-2023-30619?
Yes, there is a fix available. Please refer to the provided references for more information on the fix.