XSS in the Gantt chart of the tracker plugin
Package
Tuleap Community Edition
(tuleap)
Affected versions
< 16.1.99.50
Patched versions
16.1.99.50
Tuleap Enterprise Edition
(tuleap)
< 16.1-4
< 16.0-7
16.1-4
16.0-7
Impact
A malicious user with the ability to create an artifact in a tracker with a Gantt chart could force a victim to execute uncontrolled code.
Patches
The following versions contain the fix:
For more information
If you have any questions or comments about this advisory, reach out to us via the contact information provided on the Tuleap.org security page.
References