← Back

CVE-2025-64498

nvd nist
Published: Dec 8, 2025Modified: Dec 10, 2025

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

Tuleap is an Open Source Suite for management of software development and collaboration. Tuleap Community Edition versions below 17.0.99.1762444754 and Tuleap Enterprise Edition versions prior to 17.0-2, 16.13-7 and 16.12-10 allow attackers trick victims into changing tracker general settings. This issue is fixed in version Tuleap Community Edition version 17.0.99.1762444754 and Tuleap Enterprise Edition versions 17.0-2, 16.13-7 and 16.12-10.

Affected (4)

Products: Enalean: Tuleap
1 product
Tuleap
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Enalean
Before 17.0.99.1762444754
Before 16.12-10
From 16.13 to 16.13-7
From 17.0 to 17.0-2

References (4)

Source: security-advisories@github.com
Vendor Advisory
Source: security-advisories@github.com
Issue TrackingVendor Advisory

Timeline

No history available yet.