Vulnerability Description
Tuleap is an open source suite to improve management of software developments and collaboration. Prior to version 15.2.99.103 of Tuleap Community Edition and prior to versions 15.2-4 and 15.1-8 of Tuleap Enterprise Edition, the name of the releases are not properly escaped on the edition page of a release. A malicious user with the ability to create a FRS release could force a victim having write permissions in the FRS to execute uncontrolled code. Tuleap Community Edition 15.2.99.103, Tuleap Enterprise Edition 15.2-4, and Tuleap Enterprise Edition 15.1-8 contain a fix for this issue.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Enalean | Tuleap | < 15.1-8 |
Related Weaknesses (CWE)
References
- https://github.com/Enalean/tuleap/commit/ea71ec7ee062aae8d1fa7a7325aaa759205c17dPatch
- https://github.com/Enalean/tuleap/security/advisories/GHSA-3m7g-7787-wc68Vendor Advisory
- https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=ea71ec7ee062aae8dPatch
- https://tuleap.net/plugins/tracker/?aid=35143PatchVendor Advisory
- https://github.com/Enalean/tuleap/commit/ea71ec7ee062aae8d1fa7a7325aaa759205c17dPatch
- https://github.com/Enalean/tuleap/security/advisories/GHSA-3m7g-7787-wc68Vendor Advisory
- https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=ea71ec7ee062aae8dPatch
- https://tuleap.net/plugins/tracker/?aid=35143PatchVendor Advisory
FAQ
What is CVE-2023-48715?
CVE-2023-48715 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Tuleap is an open source suite to improve management of software developments and collaboration. Prior to version 15.2.99.103 of Tuleap Community Edition and prior to versions 15.2-4 and 15.1-8 of Tul...
How severe is CVE-2023-48715?
CVE-2023-48715 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-48715?
Check the references section above for vendor advisories and patch information. Affected products include: Enalean Tuleap.