Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap has missing CSRF protections on artifact submission & edition from the tracker view. An attacker could use this vulnerability to trick victims into submitting or editing artifacts or follow-up comments. The vulnerability is fixed in Tuleap Community Edition 16.5.99.1741784483 and Tuleap Enterprise Edition 16.5-3 and 16.4-8.
Metrics
Affected Vendors & Products
References
History
Mon, 31 Mar 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 31 Mar 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap has missing CSRF protections on artifact submission & edition from the tracker view. An attacker could use this vulnerability to trick victims into submitting or editing artifacts or follow-up comments. The vulnerability is fixed in Tuleap Community Edition 16.5.99.1741784483 and Tuleap Enterprise Edition 16.5-3 and 16.4-8. | |
Title | Tuleap has missing CSRF protections on artifact submission & edition from the tracker view | |
Weaknesses | CWE-352 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-03-31T15:38:00.273Z
Updated: 2025-03-31T18:36:27.728Z
Reserved: 2025-03-11T14:23:00.473Z
Link: CVE-2025-29766

Updated: 2025-03-31T16:12:47.580Z

Status : Awaiting Analysis
Published: 2025-03-31T16:15:23.897
Modified: 2025-04-01T20:26:22.890
Link: CVE-2025-29766

No data.