Deleting or moving an artifact can delete values from unrelated artifacts
Package
Tuleap Community Edition
(tuleap)
Affected versions
>= 14.11.99.34 && < 15.7.99.6
Patched versions
15.7.99.6
Tuleap Enterprise Edition
(tuleap)
>= 15.7-1 && < 15.7-2
>= 15.6-1 && < 15.6-5
>= 15.5-1 && < 15.5-6
>= 15.4-1 && < 15.4-8
>= 15.3-1 && < 15.3-6
>= 15.2-1 && < 15.2-5
>= 15.1-1 && < 15.1-9
>= 15.0-1 && < 15.0-9
>= 14.12-1 && < 14.12-6
15.7-2
15.6-5
15.5-6
15.4-8
15.3-6
15.2-5
15.1-9
15.0-9
14.12-6
Impact
A malicious user could exploit this issue on purpose to delete information on the instance. It is however not possible to control exactly which information is deleted.
Information from the following fields can be impacted:
Patches
The following versions contain the fix:
For more information
If you have any questions or comments about this advisory, reach out to us via the contact information provided on the Tuleap.org security page.
References