Artifact permissions are not verified in the Cross Tracker Search widget
Package
Tuleap Community Edition
(tuleap)
Affected versions
< 16.3.99.1737562605
Patched versions
16.3.99.1737562605
Tuleap Enterprise Edition
(tuleap)
< 16.3-5
< 16.2-7
16.3-5
16.2-7
Impact
Users (possibly anonymous ones if the widget is used in the dashboard of a public project) might get access to artifacts they should not see.
Patches
The following versions contain the fix:
For more information
If you have any questions or comments about this advisory, reach out to us via the contact information provided on the Tuleap.org security page.
References