CVE-2025-29766

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
31/03/2025
Last modified:
21/08/2025

Description

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap has missing CSRF protections on artifact submission & edition from the tracker view. An attacker could use this vulnerability to trick victims into submitting or editing artifacts or follow-up comments. The vulnerability is fixed in Tuleap Community Edition 16.5.99.1741784483 and Tuleap Enterprise Edition 16.5-3 and 16.4-8.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:* 16.4-8 (excluding)
cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:* 16.5.99.1741784483 (excluding)
cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:* 16.5 (including) 16.5-3 (excluding)