Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap has missing CSRF protections on artifact submission & edition from the tracker view. An attacker could use this vulnerability to trick victims into submitting or editing artifacts or follow-up comments. The vulnerability is fixed in Tuleap Community Edition 16.5.99.1741784483 and Tuleap Enterprise Edition 16.5-3 and 16.4-8.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-03-31 16:15
Updated : 2025-08-21 22:09
NVD link : CVE-2025-29766
Mitre link : CVE-2025-29766
CVE.ORG link : CVE-2025-29766
JSON object : View
Products Affected
enalean
- tuleap
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
