CVE-2023-38508
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2023-38508 affects Tuleap, an open-source software development and collaboration suite. In versions prior to Tuleap Community Edition 14.11.99.28 and Tuleap Enterprise Edition 14.10-6, 14.11-3, the preview of an artifact link with a specific type does not adhere to project, tracker, and artifact level permissions. This vulnerability enables users to access restricted information through the artifact view; however, only the title, status, assigned to, and last update date fields are impacted. Users with strict permissions for these fields remain unaffected. Tuleap Community Edition 14.11.99.28 and Tuleap Enterprise Edition 14.10-6, 14.11-3 provide resolutions for this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Enalean Tuleap
Affected Vendors
- Enalean