XSS on the edition page of a release
Package
Tuleap Community Edition
(tuleap)
Affected versions
< 15.2.99.103
Patched versions
15.2.99.103
Tuleap Enterprise Edition
(tuleap)
< 15.2-4
< 15.1-8
15.2-4
15.1-8
The name of the releases are not properly escaped on the edition page of a release
Impact
A malicious user with the ability to create a FRS release could force a victim having write permissions in the FRS to execute uncontrolled code.
Patches
The following versions contain the fix:
For more information
If you have any questions or comments about this advisory, reach out to us via the contact information provided on the Tuleap.org security page.
References