Permissions are incorrectly verified for project administrators in the cross tracker search widget
Package
Tuleap Community Edition
(tuleap)
Affected versions
< 15.13.99.110
Patched versions
15.13.99.110
Tuleap Enterprise Edition
(tuleap)
< 15.13-5
< 15.12-8
15.13-5
15.12-8
Impact
Administrators of project can access the content of trackers with permissions restrictions of project they are members of but not admin via the cross tracker search widget.
Patches
The following versions contain the fix:
For more information
If you have any questions or comments about this advisory, reach out to us via the contact information provided on the Tuleap.org security page.
References