CVE-2025-48991

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
25/06/2025
Last modified:
21/08/2025

Description

Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker could use a vulnerability present in Tuleap Community Edition prior to version 16.8.99.1748845907 and Tuleap Enterprise Edition prior to versions 16.8-3 and 16.7-5 to trick victims into changing the canned responses. Tuleap Community Edition 16.8.99.1748845907, Tuleap Enterprise Edition 16.8-3, and Tuleap Enterprise Edition 16.7-5 contain a fix for the vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:* 16.7-5 (excluding)
cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:* 16.8.99.1748845907 (excluding)
cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:* 16.8 (including) 16.8-3 (excluding)