CVE-2024-47767: Enalean Tuleap

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.113, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 15.12-5, users might see tracker names they should not have access to. Tuleap Community Edition 15.13.99.113, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 15.12-8 fix this issue.

Affected products

  • Enalean Tuleap: before 15.12-8 (fixed in 15.12-8); before 15.13.99.113 (fixed in 15.13.99.113); from 15.13-0, before 15.13-5 (fixed in 15.13-5)

Published 2024-10-14. Last modified 2026-06-17.