CVE-2024-25130: Tuleap's mass update clears the permissions on artifact field
Tuleap is an open source suite to improve management of software developments and collaboration. Prior to version 15.5.99.76 of Tuleap Community Edition and prior to versions 15.5-4 and 15.4-7 of Tuleap Enterprise Edition, users with a read access to a tracker where the mass update feature is used might get access to restricted information. Tuleap Community Edition 15.5.99.76, Tuleap Enterprise Edition 15.5-4, and Tuleap Enterprise Edition 15.4-7 contain a patch for this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Tuleap Community Editionto a version that resolves this vulnerability.Fixed in 15.5.99.76 - Upgrade
Upgrade
Tuleap Enterprise Editionto a version that resolves this vulnerability.Fixed in 15.5-4 - Upgrade
Upgrade
Tuleap Enterprise Editionto a version that resolves this vulnerability.Fixed in 15.4-7
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25130?
CVE-2024-25130 has a severity rating that indicates significant risk for users with read access to certain trackers in Tuleap.
How do I fix CVE-2024-25130?
To mitigate CVE-2024-25130, upgrade to Tuleap Community Edition version 15.5.99.76 or Tuleap Enterprise Edition versions 15.5-4 or 15.4-7.
Who is affected by CVE-2024-25130?
Users of Tuleap Community Edition prior to version 15.5.99.76 and Tuleap Enterprise Edition prior to versions 15.5-4 and 15.4-7 are affected by CVE-2024-25130.
What type of vulnerability is CVE-2024-25130?
CVE-2024-25130 is categorized as a privilege escalation vulnerability affecting certain user permissions in Tuleap.
What are the potential impacts of CVE-2024-25130?
The potential impacts of CVE-2024-25130 include unauthorized mass updates of tracker items by users with merely read access.