Resources of private projects can be accessed by non project members
Package
Tuleap Community Edition
(tuleap)
Affected versions
< 13.9.99.58
Patched versions
13.9.99.58
Tuleap Enterprise Edition
(tuleap)
< 13.10-1
13.10-1
Authorizations are not properly verified when creating projects or trackers from projects marked as templates.
Impact
Users can get access to information in those template projects because the permissions model is not properly enforced.
Patches
The following versions contain the fix:
For more information
If you have any questions or comments about this advisory, reach out to us via the contact information provided on the Tuleap.org security page.
References