PT-2022-24829 · Tuleap+1 · Tuleap+1

Rossettoy

+1

·

Published

2022-10-19

·

Updated

2023-07-14

·

CVE-2022-39233

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Tuleap versions 12.9.99.228 through 14.0.99.23
Description The issue concerns improper verification of authorizations when updating the branch prefix used by the GitLab repository integration. Authenticated users can change the branch prefix of any GitLab repository integration they can see via the REST endpoint PATCH /gitlab repositories/{id}, an action that should be restricted to Git administrators.
Recommendations For Tuleap versions 12.9.99.228 through 14.0.99.23, update to Tuleap Community Edition 14.0.99.24 or Tuleap Enterprise Edition 14.0-3 to resolve the issue. As a temporary workaround, consider restricting access to the PATCH /gitlab repositories/{id} endpoint to only allow Git administrators to make changes.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-39233
GHSA-3884-972X-3CCQ

Affected Products

Gitlab
Tuleap