Skip to content

Recursive permissions to document manager folder are not properly applied

Moderate
LeSuisse published GHSA-5jq5-vxmq-xrj7 Jul 22, 2024

Package

Tuleap Community Edition (tuleap)

Affected versions

< 15.10.99.128

Patched versions

15.10.99.128
Tuleap Enterprise Edition (tuleap)
< 15.10-6
< 15.9-8
15.10-6
15.9-8

Description

The checkbox "Apply same permissions to all sub-items of this folder" in the document manager permissions modal is not taken into account and always considered as unchecked. In situations where the permissions are being restricted some users might still keep, incorrectly, the possibility to edit or manage items. Only change made via the web UI are affected, changes directly made via the REST API are not impacted.

Patches

The following versions contain the fix:

  • Tuleap Community Edition 15.10.99.128
  • Tuleap Enterprise Edition 15.10-6
  • Tuleap Enterprise Edition 15.9-8

For more information

If you have any questions or comments about this advisory, reach out to us via the contact information provided on the Tuleap.org security page.

References

Severity

Moderate
4.8
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
High
Privileges required
High
User interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:H/A:N

CVE ID

CVE-2024-39902

Weaknesses