漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Tuleap is missing CSRF protection in the Overview inconsistent items
Vulnerability Description
Tuleap is an Open Source Suite for management of software development and collaboration. Tuleap is missing CSRF protection in the Overview inconsistent items. An attacker could use this vulnerability to trick victims into repairing inconsistent items (creating artifact links from the release). This vulnerability is fixed in Tuleap Community Edition 17.0.99.1768924735 and Tuleap Enterprise Edition 17.2-5, 17.1-6, and 17.0-9.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
Vulnerability Type
跨站请求伪造(CSRF)
Vulnerability Title
Tuleap 跨站请求伪造漏洞
Vulnerability Description
Tuleap是Enalean开源的一个开源套件,旨在改善软件开发和协作的管理。 Tuleap存在跨站请求伪造漏洞,该漏洞源于Overview不一致项缺少CSRF保护,可能导致诱骗受害者修复不一致项。
CVSS Information
N/A
Vulnerability Type
N/A