CVE-2024-23344: Tuleap's content of artifacts might be readable by unauthorized users

Published Feb 6, 2024
·
Updated

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Some users might get access to restricted information when a process validates the permissions of multiple users (e.g. mail notifications). This issue has been patched in version 15.4.99.140 of Tuleap Community Edition.

Affected Software

2 affected components
Enalean Tuleap<15.3.5
Enalean Tuleap>=15.2.99.49<15.4.99.140

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Tuleap Community Edition to a version that resolves this vulnerability.

    Fixed in 15.4.99.140

Event History

Feb 6, 2024
CVE Published
via MITRE·03:58 PM
Data Sourced
via MITRE·03:58 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-23344?

CVE-2024-23344 is considered a medium severity vulnerability due to improper permission validation that may allow unauthorized access to restricted information.

2

How do I fix CVE-2024-23344?

To mitigate CVE-2024-23344, upgrade Tuleap to version 15.4.99 or later as the issue has been patched in this release.

3

Which versions of Tuleap are affected by CVE-2024-23344?

CVE-2024-23344 affects Tuleap versions prior to 15.4.99, specifically versions 15.2.99.49 up to 15.4.99.140.

4

What type of information could be leaked due to CVE-2024-23344?

CVE-2024-23344 could potentially allow unauthorized users to access restricted information through processes like mail notifications that validate user permissions.

5

Is there a workaround for CVE-2024-23344?

There is no specific workaround for CVE-2024-23344; applying the available patch by upgrading to the latest version is recommended.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203