Lucene search

K
cvelistGitHub_MCVELIST:CVE-2023-39521
HistoryAug 24, 2023 - 10:40 p.m.

CVE-2023-39521 Tuleap vulnerable to Cross-site Scripting on the success message of a kanban deletion

2023-08-2422:40:02
CWE-79
GitHub_M
www.cve.org
1
tuleap
cross-site scripting
kanban
deletion
content
escaped
agile dashboard
administrator
code
fix
cve-2023-39521

4.8 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

5.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

24.2%

Tuleap is an open source suite to improve management of software developments and collaboration. In Tuleap Community Edition prior to version 14.11.99.28 and Tuleap Enterprise Edition prior to versions 14.10-6 and 14.11-3, content displayed in the “card fields” (visible in the kanban and PV2 apps) is not properly escaped. An agile dashboard administrator deleting a kanban with a malicious label can be forced to execute uncontrolled code. Tuleap Community Edition 14.11.99.28, Tuleap Enterprise Edition 14.10-6, and Tuleap Enterprise Edition 14.11-3 contain a fix for this issue.

CNA Affected

[
  {
    "vendor": "Enalean",
    "product": "tuleap",
    "versions": [
      {
        "version": "Tuleap Community Edition < 14.11.99.28",
        "status": "affected"
      },
      {
        "version": "Tuleap Enterprise Edition < 14.10-6",
        "status": "affected"
      },
      {
        "version": "Tuleap Enterprise Edition >= 14.11, < 14.11-3",
        "status": "affected"
      }
    ]
  }
]

4.8 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

5.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

24.2%

Related for CVELIST:CVE-2023-39521