Tuleap is an Open Source Suite to improve management of software developments and collaboration. A malicious user could exploit this issue on purpose to delete information on the instance or possibly gain access to restricted artifacts. It is however not possible to control exactly which information is deleted. Information from theDate, File, Float, Int, List, OpenList, Text, and Permissions on artifact (this one can lead to the disclosure of restricted information) fields can be impacted. This vulnerability is fixed in Tuleap Community Edition version 15.7.99.6 and Tuleap Enterprise Edition 15.7-2, 15.6-5, 15.5-6, 15.4-8, 15.3-6, 15.2-5, 15.1-9, 15.0-9, and 14.12-6.
References
Link | Resource |
---|---|
https://github.com/Enalean/tuleap/commit/a0ba0ae82a29eb8bfacef286778e5e49954f5316 | Patch |
https://github.com/Enalean/tuleap/security/advisories/GHSA-jc7g-4pcv-8jcj | Third Party Advisory |
https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=a0ba0ae82a29eb8bfacef286778e5e49954f5316 | Permissions Required |
https://tuleap.net/plugins/tracker/?aid=37545 | Issue Tracking Third Party Advisory |
https://github.com/Enalean/tuleap/commit/a0ba0ae82a29eb8bfacef286778e5e49954f5316 | Patch |
https://github.com/Enalean/tuleap/security/advisories/GHSA-jc7g-4pcv-8jcj | Third Party Advisory |
https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=a0ba0ae82a29eb8bfacef286778e5e49954f5316 | Permissions Required |
https://tuleap.net/plugins/tracker/?aid=37545 | Issue Tracking Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
07 May 2025, 17:33
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-Other | |
References | () https://github.com/Enalean/tuleap/commit/a0ba0ae82a29eb8bfacef286778e5e49954f5316 - Patch | |
References | () https://github.com/Enalean/tuleap/security/advisories/GHSA-jc7g-4pcv-8jcj - Third Party Advisory | |
References | () https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=a0ba0ae82a29eb8bfacef286778e5e49954f5316 - Permissions Required | |
References | () https://tuleap.net/plugins/tracker/?aid=37545 - Issue Tracking, Third Party Advisory | |
CPE | cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:* cpe:2.3:a:enalean:tuleap:15.7-1:*:*:*:enterprise:*:*:* cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:* |
|
First Time |
Enalean
Enalean tuleap |
21 Nov 2024, 09:11
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References | () https://github.com/Enalean/tuleap/commit/a0ba0ae82a29eb8bfacef286778e5e49954f5316 - | |
References | () https://github.com/Enalean/tuleap/security/advisories/GHSA-jc7g-4pcv-8jcj - | |
References | () https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=a0ba0ae82a29eb8bfacef286778e5e49954f5316 - | |
References | () https://tuleap.net/plugins/tracker/?aid=37545 - |
29 Mar 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-29 16:15
Updated : 2025-05-07 17:33
NVD link : CVE-2024-30246
Mitre link : CVE-2024-30246
CVE.ORG link : CVE-2024-30246
JSON object : View
Products Affected
enalean
- tuleap
CWE
CWE-440
Expected Behavior Violation
CWE-670Always-Incorrect Control Flow Implementation
NVD-CWE-Other