Project "homepage"/dashboards does not correctly verify permissions
Package
Tuleap Community Edition
(tuleap)
Affected versions
< 14.2.99.104
Patched versions
14.2.99.104
Tuleap Enterprise Edition
(tuleap)
>= 14.2-1 && < 14.2.-4
< 14.1-5
14.2-4
14.1-5
Project level authorizations are not properly verified when accessing the project "homepage"/dashboards.
Impact
Users not able to access a project might still be able to get some information provided by the widgets (e.g. number of members, content of the Notes widget...).
Patches
The following versions contain the fix:
For more information
If you have any questions or comments about this advisory, reach out to us via the contact information provided on the Tuleap.org security page.
References