An issue was discovered in Enalean Tuleap before 10.5. Reset password links are not invalidated after a user changes its password.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HEnalean Tuleap
APPEnalean< 10.5
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References
Related vulnerabilities
CVE-2018-7538CRITICAL9.8PL ✓same product
SQL Injection w module tracker platformy Enalean Tuleap
CVE-2024-30246HIGH7.6same product
Tuleap is an Open Source Suite to improve management of software developments and collaboration. A malicious u...
CVE-2022-31058HIGH7.2same product
Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In vers...
CVE-2021-43806HIGH8.8same product
Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. In ...
CVE-2021-41154HIGH8.8same product
Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affe...