CVE-2024-46988: Enalean Tuleap
Medium severity, CVSS 5.7. EPSS: 0.4% chance of exploitation in the next 30 days.
Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.40, Tuleap Enterprise Edition 15.13-3, and Tuleap Enterprise Edition 15.12-6, users might receive email notification with information they should not have access to. Tuleap Community Edition 15.13.99.40, Tuleap Enterprise Edition 15.13-3, and Tuleap Enterprise Edition 15.12-6 fix this issue.
Affected products
- Enalean Tuleap: before 15.12-6 (fixed in 15.12-6); before 15.13.99.40 (fixed in 15.13.99.40); from 15.13-0, before 15.13-3 (fixed in 15.13-3)
Published 2024-10-14. Last modified 2026-06-17.