XSS in the HTML mail content of the cross reference field
Package
Tuleap Community Edition
(tuleap)
Affected versions
< 15.13.99.37
Patched versions
15.13.99.37
Tuleap Enterprise Edition
(tuleap)
< 15.13-3
< 15.12-6
15.13-3
15.12-6
Impact
A site administrator could create an artifact link type with a forward label allowing to execute uncontrolled code (or at least achieve content injection) in a mail client.
Patches
The following versions contain the fix:
For more information
If you have any questions or comments about this advisory, reach out to us via the contact information provided on the Tuleap.org security page.
References