XSS in the tooltip via an artifact title
Vulnerability Description
Tuleap Open ALM is a Libre and Open Source tool for end to end traceability of application and system developments. The title of an artifact is not properly escaped in the tooltip. A malicious user with the capability to create an artifact or to edit a field title could force victim to execute uncontrolled code. This issue has been patched in version 14.7.99.143.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-30619
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/Enalean/tuleap/security/advisories/GHSA-7fm3-cr3g-5922
- https://github.com/Enalean/tuleap/commit/fdc93a736cbccad05de16ff0cc7cc3ef18dc93df
- https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=fdc93a736cbccad05de16ff0cc7cc3ef18dc93df
- https://tuleap.net/plugins/tracker/?aid=31586
More from Enalean
View All →Affected Vendor
Enalean
View all reports →