Tuleap is an Open Source Suite to improve management of software developments and collaboration. Backlog item representations do not verify the permissions of the child trackers. Users might see tracker names they should not have access to. This vulnerability is fixed in Tuleap Community Edition 16.11.99.1757427600 and Tuleap Enterprise Edition 16.11-6 and 16.10-8.
Metrics
Affected Vendors & Products
References
History
Mon, 22 Sep 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 19 Sep 2025 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Enalean
Enalean tuleap |
|
Vendors & Products |
Enalean
Enalean tuleap |
Thu, 18 Sep 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Backlog item representations do not verify the permissions of the child trackers. Users might see tracker names they should not have access to. This vulnerability is fixed in Tuleap Community Edition 16.11.99.1757427600 and Tuleap Enterprise Edition 16.11-6 and 16.10-8. | |
Title | Tuleap backlog item representations do not verify the permissions of the child trackers | |
Weaknesses | CWE-280 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-09-18T14:28:41.999Z
Updated: 2025-09-22T17:21:55.603Z
Reserved: 2025-09-08T16:19:26.171Z
Link: CVE-2025-59040

Updated: 2025-09-22T17:21:52.728Z

Status : Awaiting Analysis
Published: 2025-09-18T15:15:38.370
Modified: 2025-09-19T16:00:27.847
Link: CVE-2025-59040

No data.