CVE-2024-46988: Tuleap does not properly check permissions for email notifications in trackers
Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.40, Tuleap Enterprise Edition 15.13-3, and Tuleap Enterprise Edition 15.12-6, users might receive email notification with information they should not have access to. Tuleap Community Edition 15.13.99.40, Tuleap Enterprise Edition 15.13-3, and Tuleap Enterprise Edition 15.12-6 fix this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-46988?
CVE-2024-46988 has a moderate severity rating due to potential exposure of sensitive information in email notifications.
How do I fix CVE-2024-46988?
To fix CVE-2024-46988, upgrade to Tuleap Community Edition version 15.13.99.40 or later, or Tuleap Enterprise Edition version 15.13-3 or later.
Which versions are affected by CVE-2024-46988?
CVE-2024-46988 affects Tuleap Community Edition versions prior to 15.13.99.40 and Tuleap Enterprise Edition versions prior to 15.13-3 and 15.12-6.
What kind of information might be exposed due to CVE-2024-46988?
Due to CVE-2024-46988, users may receive email notifications containing sensitive information that they should not have access to.
Who is impacted by CVE-2024-46988?
All users of Tuleap versions prior to the specified fixed versions may be impacted by CVE-2024-46988.