Missing CSRF protections in the management of tracker triggers
Package
Tuleap Community Edition
(tuleap)
Affected versions
< 17.0.99.1763126988
Patched versions
17.0.99.1763126988
Tuleap Enterprise Edition
(tuleap)
< 17.0-3
< 16.13-8
17.0-3
16.13-8
Impact
An attacker could use this vulnerability to trick victims into creating or removing a tracker trigger.
Patches
The following versions contain the fix:
For more information
If you have any questions or comments about this advisory, reach out to us via the contact information provided on the Tuleap.org security page.
References