CVE-2025-48991
Severity CVSS v4.0:
Pending analysis
Type:
CWE-352
Cross-Site Request Forgery (CSRF)
Publication date:
25/06/2025
Last modified:
21/08/2025
Description
Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker could use a vulnerability present in Tuleap Community Edition prior to version 16.8.99.1748845907 and Tuleap Enterprise Edition prior to versions 16.8-3 and 16.7-5 to trick victims into changing the canned responses. Tuleap Community Edition 16.8.99.1748845907, Tuleap Enterprise Edition 16.8-3, and Tuleap Enterprise Edition 16.7-5 contain a fix for the vulnerability.
Impact
Base Score 3.x
4.60
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:* | 16.7-5 (excluding) | |
cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:* | 16.8.99.1748845907 (excluding) | |
cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:* | 16.8 (including) | 16.8-3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://github.com/Enalean/tuleap/commit/cbf9b2a38e33dfd755dc2ccf074126b598a78274
- https://github.com/Enalean/tuleap/security/advisories/GHSA-px9r-875r-w534
- https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=cbf9b2a38e33dfd755dc2ccf074126b598a78274
- https://tuleap.net/plugins/tracker/?aid=43326