CVE-2024-52599

Tuleap is an open source suite to improve management of software developments and collaboration. In Tuleap Community Edition prior to version 16.1.99.50 and Tuleap Enterprise Edition prior to versions 16.1-4 and 16.0-7, a malicious user with the ability to create an artifact in a tracker with a Gantt chart could force a victim to execute uncontrolled code. Tuleap Community Edition 16.1.99.50, Tuleap Enterprise Edition 16.1-4, and Tuleap Enterprise Edition 16.0-7 contain a fix.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*

History

22 Aug 2025, 16:19

Type Values Removed Values Added
CPE cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*
First Time Enalean
Enalean tuleap
References () https://github.com/Enalean/tuleap/commit/d3686ab152b6f64ff835e7dd3c99d97b36a9d4d5 - () https://github.com/Enalean/tuleap/commit/d3686ab152b6f64ff835e7dd3c99d97b36a9d4d5 - Patch
References () https://github.com/Enalean/tuleap/security/advisories/GHSA-489c-fm2j-qjw7 - () https://github.com/Enalean/tuleap/security/advisories/GHSA-489c-fm2j-qjw7 - Third Party Advisory, Patch
References () https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=d3686ab152b6f64ff835e7dd3c99d97b36a9d4d5 - () https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=d3686ab152b6f64ff835e7dd3c99d97b36a9d4d5 - Permissions Required
References () https://tuleap.net/plugins/tracker/?aid=40459 - () https://tuleap.net/plugins/tracker/?aid=40459 - Third Party Advisory, Issue Tracking, Patch, Exploit
Summary
  • (es) Tuleap es una suite de código abierto para mejorar la gestión de los desarrollos de software y la colaboración. En Tuleap Community Edition anterior a la versión 16.1.99.50 y Tuleap Enterprise Edition anterior a las versiones 16.1-4 y 16.0-7, un usuario malintencionado con la capacidad de crear un artefacto en un rastreador con un diagrama de Gantt podría obligar a una víctima a ejecutar código no controlado. Tuleap Community Edition 16.1.99.50, Tuleap Enterprise Edition 16.1-4 y Tuleap Enterprise Edition 16.0-7 contienen una corrección.

09 Dec 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-09 19:15

Updated : 2025-08-22 16:19


NVD link : CVE-2024-52599

Mitre link : CVE-2024-52599

CVE.ORG link : CVE-2024-52599


JSON object : View

Products Affected

enalean

  • tuleap
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')