Medium severity4.3NVD Advisory· Published Jun 9, 2022· Updated Jun 17, 2026
CVE-2022-24896
CVE-2022-24896
Description
Tuleap is a Free & Open Source Suite to manage software developments and collaboration. In versions prior to 13.7.99.239 Tuleap does not properly verify authorizations when displaying the content of tracker report renderer and chart widgets. Malicious users could use this vulnerability to retrieve the name of a tracker they cannot access as well as the name of the fields used in reports.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4Patches
Vulnerability mechanics
References
4- github.com/Enalean/tuleap/commit/8e99e7c82d9fe569799019b9e1d614d38a184313nvdPatchThird Party Advisory
- github.com/Enalean/tuleap/security/advisories/GHSA-x962-x43g-qw39nvdPatchThird Party Advisory
- tuleap.net/plugins/git/tuleap/tuleap/stablenvdPatchVendor Advisory
- tuleap.net/plugins/tracker/nvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.