PT-2022-24829 · Tuleap+1 · Tuleap+1
Rossettoy
+1
·
Published
2022-10-19
·
Updated
2023-07-14
·
CVE-2022-39233
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Tuleap versions 12.9.99.228 through 14.0.99.23
Description
The issue concerns improper verification of authorizations when updating the branch prefix used by the GitLab repository integration. Authenticated users can change the branch prefix of any GitLab repository integration they can see via the REST endpoint
PATCH /gitlab repositories/{id}, an action that should be restricted to Git administrators.Recommendations
For Tuleap versions 12.9.99.228 through 14.0.99.23, update to Tuleap Community Edition 14.0.99.24 or Tuleap Enterprise Edition 14.0-3 to resolve the issue.
As a temporary workaround, consider restricting access to the
PATCH /gitlab repositories/{id} endpoint to only allow Git administrators to make changes.Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gitlab
Tuleap