Trackers are listed in the quick add actions of the backlog without any permissions check
Package
Tuleap Community Edition
(tuleap)
Affected versions
< 15.13.99.113
Patched versions
15.13.99.113
Tuleap Enterprise Edition
(tuleap)
< 15.13-5
< 15.12-8
15.13-5
15.12-8
Impact
Users might see tracker names they should not have access to.
Patches
The following versions contain the fix:
For more information
If you have any questions or comments about this advisory, reach out to us via the contact information provided on the Tuleap.org security page.
References