CVE-2024-37167

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Users are able to see backlog items that they should not see. This issue has been patched in Tuleap Community Edition version 15.9.99.97.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*

History

22 Aug 2025, 15:43

Type Values Removed Values Added
CPE cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:*
References () https://github.com/Enalean/tuleap/commit/13eec93a353d2daf47bb8b9c548cc02f78b93a5e - () https://github.com/Enalean/tuleap/commit/13eec93a353d2daf47bb8b9c548cc02f78b93a5e - Patch
References () https://github.com/Enalean/tuleap/security/advisories/GHSA-4c9f-284j-phvj - () https://github.com/Enalean/tuleap/security/advisories/GHSA-4c9f-284j-phvj - Vendor Advisory
References () https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=13eec93a353d2daf47bb8b9c548cc02f78b93a5e - () https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=13eec93a353d2daf47bb8b9c548cc02f78b93a5e - Broken Link
References () https://tuleap.net/plugins/tracker/?aid=38297 - () https://tuleap.net/plugins/tracker/?aid=38297 - Vendor Advisory
First Time Enalean
Enalean tuleap

Information

Published : 2024-06-25 20:15

Updated : 2025-08-22 15:43


NVD link : CVE-2024-37167

Mitre link : CVE-2024-37167

CVE.ORG link : CVE-2024-37167


JSON object : View

Products Affected

enalean

  • tuleap
CWE
CWE-285

Improper Authorization