The fields of a tracker can loose their configuration when they are added as a criteria of a saved report.
Impact
A malicious user with the ability to access a tracker could force reset some field configurations leading to some information loss.
The following tracker fields loose some of their configuration values when added as a criteria of a saved report:
- Date : display time attribute
- Multiselectbox: size attribute
- String: default value, size and max chars attributes
- Text: default value, number of rows and columns attributes
In addition, between Tuleap Community Edition 16.4.99.1739806825 and 16.4.99.1739877910 this issue could be used to prevent access to tracker data by provoking a crash.
CVSSv3.1 score: 5.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L)
Reproduction scenario
- Create a datetime field
- Add it in a report
- Save the report
- Go back in tracker administration, your field date is no longer a datetime (it should)
References
CWE 440
CVE-2025-27094