Description
Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker can access release notes content or information via the FRS REST endpoints it should not have access to. This vulnerability is fixed in Tuleap Community Edition 16.5.99.1742812323 and Tuleap Enterprise Edition 16.5-6 and 16.4-10.
References (4)
Core 4
Core References
Third Party Advisory x_refsource_confirm
https://github.com/Enalean/tuleap/security/advisories/GHSA-hcp5-pmpm-mgwh
Patch x_refsource_misc
https://github.com/Enalean/tuleap/commit/34af2d5d10b0349967129f53427f495815e5bbcc
Broken Link x_refsource_misc
https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=34af2d5d10b0349967129f53427f495815e5bbcc
Vendor Advisory x_refsource_misc
https://tuleap.net/plugins/tracker/?aid=42251
Scores
CVSS v3
5.3
EPSS
0.0030
EPSS Percentile
53.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-863
Status
published
Products (2)
enalean/tuleap
< 16.4-10
enalean/tuleap
< 16.5.99.1742812323
Published
Mar 31, 2025
Tracked Since
Feb 18, 2026