Tuleap is an Open Source Suite to improve management of software developments and collaboration. In versions prior to 14.2.99.104, project level authorizations are not properly verified when accessing the project "homepage"/dashboards. Users not authorized to access a project may still be able to get some information provided by the widgets (e.g. number of members, content of the Notes widget...). This issue has been patched in Tuleap Community Edition 14.2.99.104, Tuleap Enterprise Edition 14.2-4, and Tuleap Enterprise Edition 14.1-5.
History

Wed, 23 Apr 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2022-12-13T06:40:05.477Z

Updated: 2025-04-23T16:28:47.584Z

Reserved: 2022-11-28T17:27:19.997Z

Link: CVE-2022-46160

cve-icon Vulnrichment

Updated: 2024-08-03T14:24:03.397Z

cve-icon NVD

Status : Modified

Published: 2022-12-13T07:15:13.980

Modified: 2024-11-21T07:30:13.833

Link: CVE-2022-46160

cve-icon Redhat

No data.