← Back

CVE-2025-27402

nvd nist
Published: Mar 4, 2025Modified: Aug 22, 2025

JSON object

Loading...
4.6
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
Exploitability: 2.1 / Impact: 2.5
Source: security-advisories@github.com (Secondary)

Description

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap is missing CSRF protections on tracker fields administrative operations. An attacker could use this vulnerability to trick victims into removing or updating tracker fields. This vulnerability is fixed in Tuleap Community Edition 16.4.99.1740414959 and Tuleap Enterprise Edition 16.4-6 and 16.3-11.

Affected (3)

Products: Enalean: Tuleap
1 product
Tuleap
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Enalean
Before 16.4.99.1740414959
Before 16.3-11
From 16.4 to 16.4-6

References (3)

Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
Issue TrackingVendor Advisory

Timeline

No history available yet.