CVE-2025-24029

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Users (possibly anonymous ones if the widget is used in the dashboard of a public project) might get access to artifacts they should not see. This issue has been addressed in Tuleap Community Edition 16.3.99.1737562605 as well as Tuleap Enterprise Edition 16.3-5 and Tuleap Enterprise Edition 16.2-7. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*

History

No history.

Information

Published : 2025-02-03 22:15

Updated : 2025-08-22 15:59


NVD link : CVE-2025-24029

Mitre link : CVE-2025-24029

CVE.ORG link : CVE-2025-24029


JSON object : View

Products Affected

enalean

  • tuleap
CWE
CWE-280

Improper Handling of Insufficient Permissions or Privileges