Medium severity4.3NVD Advisory· Published Jun 29, 2022· Updated Jun 17, 2026
CVE-2022-31032
CVE-2022-31032
Description
Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions prior to 13.9.99.58 authorizations are not properly verified when creating projects or trackers from projects marked as templates. Users can get access to information in those template projects because the permissions model is not properly enforced. Users are advised to upgrade. There are no known workarounds for this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5Patches
Vulnerability mechanics
References
6- github.com/Enalean/tuleap/commit/7e221a9d1893c13407b35008762757a76d8e5654nvdPatchThird Party Advisory
- github.com/Enalean/tuleap/commit/cc38bcc59ce0c733ca915d95daec5f3082fb17canvdPatchThird Party Advisory
- tuleap.net/plugins/git/tuleap/tuleap/stablenvdPatchVendor Advisory
- github.com/Enalean/tuleap/security/advisories/GHSA-hvx6-4228-whj3nvdThird Party Advisory
- tuleap.net/plugins/tracker/nvdIssue TrackingVendor Advisory
- docs.tuleap.org/administration-guide/users-management/security/site-access.htmlnvdProduct
News mentions
0No linked articles in our index yet.