XSS via the tracker names used in the semantic timeframe deletion message
Package
Tuleap Community Edition
(tuleap)
Affected versions
< 16.4.99.1740067916
Patched versions
16.4.99.1740067916
Tuleap Enterprise Edition
(tuleap)
< 16.4-5
< 16.3-10
16.4-5
16.3-10
Impact
A tracker administrator with a semantic timeframe used by other trackers could use this vulnerability to force other tracker administrators to execute uncontrolled code.
Patches
The following versions contain the fix:
For more information
If you have any questions or comments about this advisory, reach out to us via the contact information provided on the Tuleap.org security page.
References