Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-24896

Tuleap is a Free & Open Source Suite to manage software developments and collaboration. In versions prior to 13.7.99.239 Tuleap does not properly verify authorizations when displaying the content of tracker report renderer and chart widgets. Malicious users could use this vulnerability to retrieve the name of a tracker they cannot access as well as the name of the fields used in reports.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 37.3%
CVSS Severity
CVSS v3 Score 4.3
CVSS v2 Score 4.0
Products affected by CVE-2022-24896
  • Enalean » Tuleap » Version: N/A
    cpe:2.3:a:enalean:tuleap:-
  • Enalean » Tuleap » Version: 11.15-1
    cpe:2.3:a:enalean:tuleap:11.15-1
  • Enalean » Tuleap » Version: 11.15-8
    cpe:2.3:a:enalean:tuleap:11.15-8
  • Enalean » Tuleap » Version: 11.16-1
    cpe:2.3:a:enalean:tuleap:11.16-1
  • Enalean » Tuleap » Version: 11.16-6
    cpe:2.3:a:enalean:tuleap:11.16-6
  • Enalean » Tuleap » Version: 11.16-7
    cpe:2.3:a:enalean:tuleap:11.16-7
  • Enalean » Tuleap » Version: 11.16.99.173
    cpe:2.3:a:enalean:tuleap:11.16.99.173
  • Enalean » Tuleap » Version: 11.17-1
    cpe:2.3:a:enalean:tuleap:11.17-1
  • Enalean » Tuleap » Version: 11.17-5
    cpe:2.3:a:enalean:tuleap:11.17-5
  • Enalean » Tuleap » Version: 11.17.99.144
    cpe:2.3:a:enalean:tuleap:11.17.99.144
  • Enalean » Tuleap » Version: 11.17.99.146
    cpe:2.3:a:enalean:tuleap:11.17.99.146
  • Enalean » Tuleap » Version: 12.10
    cpe:2.3:a:enalean:tuleap:12.10
  • Enalean » Tuleap » Version: 12.11-2
    cpe:2.3:a:enalean:tuleap:12.11-2
  • Enalean » Tuleap » Version: 12.9.99.228
    cpe:2.3:a:enalean:tuleap:12.9.99.228
  • Enalean » Tuleap » Version: 13.7-1
    cpe:2.3:a:enalean:tuleap:13.7-1


Contact Us

Shodan ® - All rights reserved