CVE-2024-23344: Tuleap's content of artifacts might be readable by unauthorized users
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Some users might get access to restricted information when a process validates the permissions of multiple users (e.g. mail notifications). This issue has been patched in version 15.4.99.140 of Tuleap Community Edition.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Tuleap Community Editionto a version that resolves this vulnerability.Fixed in 15.4.99.140
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23344?
CVE-2024-23344 is considered a medium severity vulnerability due to improper permission validation that may allow unauthorized access to restricted information.
How do I fix CVE-2024-23344?
To mitigate CVE-2024-23344, upgrade Tuleap to version 15.4.99 or later as the issue has been patched in this release.
Which versions of Tuleap are affected by CVE-2024-23344?
CVE-2024-23344 affects Tuleap versions prior to 15.4.99, specifically versions 15.2.99.49 up to 15.4.99.140.
What type of information could be leaked due to CVE-2024-23344?
CVE-2024-23344 could potentially allow unauthorized users to access restricted information through processes like mail notifications that validate user permissions.
Is there a workaround for CVE-2024-23344?
There is no specific workaround for CVE-2024-23344; applying the available patch by upgrading to the latest version is recommended.