XSS via the content of RSS feeds in the RSS widgets
Package
Tuleap Community Edition
(tuleap)
Affected versions
< 16.5.99.1742562878
Patched versions
16.5.99.1742562878
Tuleap Enterprise Edition
(tuleap)
< 16.5-5
< 16.4-8
16.5-5
16.4-8
Impact
A project administrator or someone with control over an used RSS feed could use this vulnerability to force victims to execute uncontrolled code.
Patches
The following versions contain the fix:
For more information
If you have any questions or comments about this advisory, reach out to us via the contact information provided on the Tuleap.org security page.
References