CVE-2022-23473 Information

Description

Tuleap is an Open Source Suite to improve management of software developments and collaboration. In versions prior to 14.2.99.148 Authorizations are not properly verified when accessing MediaWiki standalone resources. Users with read only permissions for pages are able to also edit them. This only affects the MediaWiki standalone plugin. This issue is patched in versions Tuleap Community Edition 14.2.99.148 Tuleap Enterprise Edition 14.2-5 and Tuleap Enterprise Edition 14.1-6.

Reference

https://tuleap.net/plugins/tracker/?aid=29645 https://github.com/Enalean/tuleap/security/advisories/GHSA-c7rr-5vmc-rgcw https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=97cac78302170a883c1d60c9fa6dfd0d95854cb9

Share on: