•  
      request #41434 Initial effort field does not respect field permissions in the Taskboard REST card representation
    Infos
    #41434
    Thomas Gerbet (tgerbet)
    2025-02-03 09:33
    2025-01-06 17:05
    43089
    Details
    Initial effort field does not respect field permissions in the Taskboard REST card representation

    The initial effort field permissions are not respected when retrieving the cards of a Taskboard.

    Impact

    An unauthorized user might get access to restricted information.
    CVSSv3.1 score: 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)

    Exploitation

    Restrict the initial effort field of a tracker used with the Taskboard plugin to the project administrators.
    With a user that is not a project administrators try to access cards on one of the following REST endpoints (or just display the taskboard):

    • taskboard/:id/cards
    • taskboard_cards/:id
    • taskboard_cards/:id/children

    References

    CWE 280
    CVE-2025-22129

    Agile Dashboard
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Thomas Gerbet (tgerbet)
    Closed
    2025-01-07
    Attachments
    Empty
    References

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2025-01-08 09:13

    CVE-2025-22129 has been assigned to this issue.


    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes
    User avatar
    Thomas Gerbet (tgerbet)2025-01-06 17:09
    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes