CVE-2024-46980: Tuleap vulnerable to XSS in the HTML mail content of the cross reference field
Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.37, Tuleap Enterprise Edition 15.13-3, and Tuleap Enterprise Edition 15.12-6, a site administrator could create an artifact link type with a forward label allowing them to execute uncontrolled code (or at least achieve content injection) in a mail client. Tuleap Community Edition 15.13.99.37, Tuleap Enterprise Edition 15.13-3, and Tuleap Enterprise Edition 15.12-6 fix this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-46980?
CVE-2024-46980 has a medium severity rating due to the potential for improper access control in Tuleap.
How do I fix CVE-2024-46980?
To fix CVE-2024-46980, upgrade to Tuleap Community Edition 15.13.99.37, Tuleap Enterprise Edition 15.13-3, or Tuleap Enterprise Edition 15.12-6.
Which versions of Tuleap are affected by CVE-2024-46980?
CVE-2024-46980 affects Tuleap Community Edition versions prior to 15.13.99.37 and Tuleap Enterprise Edition versions prior to 15.13-3 and 15.12-6.
What type of vulnerability is CVE-2024-46980?
CVE-2024-46980 is a vulnerability related to improper access control in Tuleap.
Who is impacted by CVE-2024-46980?
Site administrators using affected versions of Tuleap may be impacted by CVE-2024-46980.