CVE-2024-46980: Enalean Tuleap

Medium severity, CVSS 4.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.37, Tuleap Enterprise Edition 15.13-3, and Tuleap Enterprise Edition 15.12-6, a site administrator could create an artifact link type with a forward label allowing them to execute uncontrolled code (or at least achieve content injection) in a mail client. Tuleap Community Edition 15.13.99.37, Tuleap Enterprise Edition 15.13-3, and Tuleap Enterprise Edition 15.12-6 fix this issue.

Affected products

  • Enalean Tuleap: before 15.12-6 (fixed in 15.12-6); before 15.13.99.37 (fixed in 15.13.99.37); from 15.13-0, before 15.13-3 (fixed in 15.13-3)

Published 2024-10-14. Last modified 2026-06-17.