CVE-2024-52599: Tuleap vulnerable to XSS in the Gantt chart of the tracker plugin
Tuleap is an open source suite to improve management of software developments and collaboration. In Tuleap Community Edition prior to version 16.1.99.50 and Tuleap Enterprise Edition prior to versions 16.1-4 and 16.0-7, a malicious user with the ability to create an artifact in a tracker with a Gantt chart could force a victim to execute uncontrolled code. Tuleap Community Edition 16.1.99.50, Tuleap Enterprise Edition 16.1-4, and Tuleap Enterprise Edition 16.0-7 contain a fix.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52599?
CVE-2024-52599 has been assessed as a high severity vulnerability due to the potential for unauthorized access and manipulation of artifacts.
How do I fix CVE-2024-52599?
To fix CVE-2024-52599, upgrade to Tuleap Community Edition version 16.1.99.50 or Tuleap Enterprise Edition versions 16.1-4 or 16.0-7.
What versions of Tuleap are affected by CVE-2024-52599?
CVE-2024-52599 affects Tuleap Community Edition prior to version 16.1.99.50 and Tuleap Enterprise Edition prior to versions 16.1-4 and 16.0-7.
Who can exploit CVE-2024-52599?
CVE-2024-52599 can be exploited by a malicious user with permission to create artifacts in the affected Tuleap versions.
What type of vulnerability is CVE-2024-52599?
CVE-2024-52599 is classified as an authorization issue that can lead to unauthorized data manipulation.