In a Cross Tracker Search widget, permissions depending on each artifact context are not correctly verified. This includes permissions like "have access to artifacts they submitted" or permissions defined by the permissions on artifact field.
Impact
Users (possibly anonymous ones if the widget is used in the dashboard of a public project) might get access to artifacts they should not see.
CVSSv3.1 score: 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitation
A tracker with artifacts accessible only to their submitter, if a CrossTrackerSearch widget search on this tracker, users may see artifacts they do not have submitted.
References
CWE-280
CVE-2025-24029