Vulnerabilidades em Enalean

62 resultados
Análise Vexday

Com 62 CVEs catalogadas e nenhuma em exploração ativa no catálogo KEV da CISA, o perfil de risco do vendor Enalean situa-se abaixo da média geral do catálogo em termos de exploração confirmada. A ausência de falhas críticas, provas de conceito públicas e registros recentes nos últimos 90 dias indica estabilidade momentânea na superfície de ataque, embora o histórico acumulado mereça monitoramento contínuo. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que, quando não mitigado sistematicamente, pode facilitar ataques de injeção de conteúdo em interfaces web. A CVE mais relevante no momento, CVE-2021-41147, apresenta EPSS de 0,018, sinalizando probabilidade de exploração relativamente baixa, mas suficiente para justificar verificação de aplicação de correções em ambientes que ainda executem versões afetadas.

CVE-2022-46160MEDIUMTuleap dashboards vulnerable to Incorrect AuthorizationEPSS 0.5%CVE-2024-25130MEDIUMTuleap's mass update clears the permissions on artifact fieldEPSS 0.5%CVE-2023-30619MEDIUMXSS in the tooltip via an artifact titleEPSS 0.5%CVE-2023-35929MEDIUMTuleap Cross-site Scripting vulnerability in the card field of the agile dashboard appsEPSS 0.5%CVE-2023-32072MEDIUMTuleap vulnerable toXSS via the triggered job URL of a Jenkins jobEPSS 0.5%CVE-2023-39521MEDIUMTuleap vulnerable to Cross-site Scripting on the success message of a kanban deletionEPSS 0.5%CVE-2023-23938MEDIUMCross-site Scripting (XSS) through the name of a color of select box values in tuleapEPSS 0.5%CVE-2022-23473MEDIUMTuleap MediaWiki standalone "readers" can also edit pagesEPSS 0.5%CVE-2024-47767MEDIUMTuleap lists trackers in the quick add actions of the backlog without any permissions checkEPSS 0.4%CVE-2025-27150MEDIUMTuleap dumps the Redis password into the generated troubleshooting archivesEPSS 0.4%CVE-2024-46980MEDIUMTuleap vulnerable to XSS in the HTML mail content of the cross reference fieldEPSS 0.4%CVE-2024-37167MEDIUMTuleap has improper permissions of the backlog itemsEPSS 0.4%CVE-2025-27094MEDIUMTuleap allows default values to be cleared from field configurationEPSS 0.4%CVE-2025-30209MEDIUMTuleap has improper permission handling in the REST endpoints and release notes display of the FRS pluginEPSS 0.4%CVE-2025-24029MEDIUMArtifact permissions are not verified in the Cross Tracker Search widget in TuleapEPSS 0.3%CVE-2024-46988MEDIUMTuleap does not properly check permissions for email notifications in trackersEPSS 0.3%CVE-2025-22129MEDIUMInitial effort field does not respect field permissions in the Taskboard REST card representation in TuleapEPSS 0.3%CVE-2025-27401MEDIUMIn Tuleap, deleting a report can delete criteria filters in other reportsEPSS 0.3%CVE-2024-52599MEDIUMTuleap vulnerable to XSS in the Gantt chart of the tracker pluginEPSS 0.3%CVE-2025-59040MEDIUMTuleap backlog item representations do not verify the permissions of the child trackersEPSS 0.3%