PT-2023-25395 · Tuleap · Tuleap

Tgerbet

+1

·

Published

2023-06-29

·

Updated

2023-07-10

·

CVE-2023-35938

CVSS v3.1

4.1

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Tuleap versions prior to 14.9.99.63
Description The issue occurs when switching from a project visibility that allows restricted users to Private without restricted, where restricted users that are project administrators retain their access rights. These users can still access the project and perform some administration actions.
Recommendations For versions prior to 14.9.99.63, upgrade to version 14.9.99.63 to resolve the issue. As a temporary workaround, consider restricting access to project administration actions for restricted users who were project administrators before the visibility switch, until the upgrade is applied.

Exploit

Fix

Improper Preservation of Permissions

Weakness Enumeration

Related Identifiers

CVE-2023-35938
GHSA-RQ42-CV6Q-3M9Q

Affected Products

Tuleap