CVE-2024-47767: Tuleap lists trackers in the quick add actions of the backlog without any permissions check
Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.113, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 15.12-5, users might see tracker names they should not have access to. Tuleap Community Edition 15.13.99.113, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 15.12-8 fix this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-47767?
CVE-2024-47767 has a medium severity rating due to unauthorized access to sensitive tracker names.
How do I fix CVE-2024-47767?
To fix CVE-2024-47767, upgrade to Tuleap Community Edition 15.13.99.113 or later, or Tuleap Enterprise Edition 15.13-5 or later.
Who is affected by CVE-2024-47767?
Users of Tuleap versions prior to Community Edition 15.13.99.113, Enterprise Edition 15.13-5, and Enterprise Edition 15.12-5 are affected.
What types of vulnerabilities does CVE-2024-47767 represent?
CVE-2024-47767 represents an access control vulnerability that could lead to information disclosure.
What versions of Tuleap are vulnerable to CVE-2024-47767?
Tuleap Community Edition versions before 15.13.99.113 and Enterprise Editions before 15.13-5 and 15.12-5 are vulnerable to CVE-2024-47767.