Permissions of the backlog items are not verified
Package
Tuleap Community Edition
(tuleap)
Affected versions
< 15.9.99.97
Patched versions
15.9.99.97
Tuleap Enterprise Edition
(tuleap)
< 15.9-3
< 15.8-5
15.9-3
15.8-5
Impact
Users might be able to see backlog items that they should not see.
Patches
The following versions contain the fix:
For more information
If you have any questions or comments about this advisory, reach out to us via the contact information provided on the Tuleap.org security page.
References