Back to Database
Status published
Medium
CVE-2024-37167
Tuleap has improper permissions of the backlog items
Vulnerability Description
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Users are able to see backlog items that they should not see. This issue has been patched in Tuleap Community Edition version 15.9.99.97.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-37167
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/Enalean/tuleap/security/advisories/GHSA-4c9f-284j-phvj
- https://github.com/Enalean/tuleap/commit/13eec93a353d2daf47bb8b9c548cc02f78b93a5e
- https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=13eec93a353d2daf47bb8b9c548cc02f78b93a5e
- https://tuleap.net/plugins/tracker/?aid=38297
More from Enalean
View All →CVE-2025-65962
Tuleap has missing CSRF protections its in tracker field dependencies
Medium
4.6
CVE-2025-64760
Tuleap has missing CSRF protections in its tracker trigger management system
Medium
4.6
CVE-2025-64499
Tuleap is missing CSRF protections for its planning management API
Medium
4.6
CVE-2025-64498
Tuleap has a Cross-Site Request Forgery (CSRF) vulnerability
Medium
4.6
CVE-2025-64497
Tuleap exposes releases for all projects to File Release System project administrators
Medium
6.5
Affected Vendor
Enalean
View all reports →Affected Software
tuleap
Vulnerable Versions:
< 15.9.99.97
Timeline
Official Publish:
June 25th, 2024
Last Modified:
August 2nd, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N