•  
      request #41849 Loss of tracker fields configuration when updating tracker report criterion
    Infos
    #41849
    Marie Ange Garnier (marieange)
    2025-03-03 09:31
    2025-02-18 14:09
    43517
    Details
    Loss of tracker fields configuration when updating tracker report criterion

    The fields of a tracker can loose their configuration when they are added as a criteria of a saved report.

    Impact

    A malicious user with the ability to access a tracker could force reset some field configurations leading to some information loss.

    The following tracker fields loose some of their configuration values when added as a criteria of a saved report:

    • Date : display time attribute
    • Multiselectbox: size attribute
    • String: default value, size and max chars attributes
    • Text: default value, number of rows and columns attributes

    In addition, between Tuleap Community Edition 16.4.99.1739806825 and 16.4.99.1739877910 this issue could be used to prevent access to tracker data by provoking a crash.

    CVSSv3.1 score: 5.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L)

    Reproduction scenario

    1. Create a datetime field
    2. Add it in a report
    3. Save the report
    4. Go back in tracker administration, your field date is no longer a datetime (it should)

    References

    CWE 440
    CVE-2025-27094

    Trackers
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Marie Ange Garnier (marieange)
    Closed
    2025-02-18
    Attachments
    Empty
    References

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2025-02-21 09:11

    CVE-2025-27094 has been assigned to this issue.


    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes
    User avatar
    Thomas Gerbet (tgerbet)2025-02-20 10:01
    • Summary
      -Default values can be cleared from field configuration 
      + Loss of tracker fields configuration when updating tracker report criterion 
    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes
    User avatar
    Thomas Gerbet (tgerbet)2025-02-18 15:42

    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes
    • Status changed from Under implementation to Under review
    • Reported in version set to All
    User avatar
    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes