CVE-2024-37167: Tuleap has improper permissions of the backlog items
Published Jun 25, 2024
·Updated
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Users are able to see backlog items that they should not see. This issue has been patched in Tuleap Community Edition version 15.9.99.97.
Affected Software
4 affected components
Tuleap Tuleap Community Edition<15.9.99.97
Enalean Tuleap<15.8-5
Enalean Tuleap<15.9.99.97
Enalean Tuleap>=15.9<15.9-3
Remediation
Event History
Jun 25, 2024
CVE Published
via MITRE·07:28 PM
Data Sourced
via MITRE·07:28 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-37167?
CVE-2024-37167 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2024-37167?
To resolve CVE-2024-37167, upgrade to Tuleap Community Edition version 15.9.99.97 or later.
3
What does CVE-2024-37167 allow users to do?
CVE-2024-37167 allows users to see backlog items that they should not have access to.
4
Which versions of Tuleap are affected by CVE-2024-37167?
CVE-2024-37167 affects all versions of Tuleap Community Edition prior to 15.9.99.97.
5
Is there a patch available for CVE-2024-37167?
Yes, a patch has been released in Tuleap Community Edition version 15.9.99.97.