Tuleap is an Open Source Suite to improve management of software developments and collaboration. In affected versions an unauthorized user might get access to restricted information. This issue has been addressed in Tuleap Community Edition 16.3.99.1736242932, Tuleap Enterprise Edition 16.2-5, and Tuleap Enterprise Edition 16.3-2. Users are advised to upgrade. There are no known workarounds for this vulnerability.
References
Link | Resource |
---|---|
https://github.com/Enalean/tuleap/security/advisories/GHSA-f34g-wc2m-mf76 | Third Party Advisory Patch |
https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=3edf8158ba40be66f0b661888b8b2805784795d1 | Permissions Required |
https://tuleap.net/plugins/tracker/?aid=41434 | Vendor Advisory Exploit Issue Tracking Patch |
https://tuleap.net/plugins/tracker/?aid=41434 | Vendor Advisory Exploit Issue Tracking Patch |
Configurations
Configuration 1 (hide)
|
History
22 Aug 2025, 16:19
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/Enalean/tuleap/security/advisories/GHSA-f34g-wc2m-mf76 - Third Party Advisory, Patch | |
References | () https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=3edf8158ba40be66f0b661888b8b2805784795d1 - Permissions Required | |
References | () https://tuleap.net/plugins/tracker/?aid=41434 - Vendor Advisory, Exploit, Issue Tracking, Patch | |
First Time |
Enalean
Enalean tuleap |
|
CPE | cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:* cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:* |
04 Feb 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References | () https://tuleap.net/plugins/tracker/?aid=41434 - |
03 Feb 2025, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-03 22:15
Updated : 2025-08-22 16:19
NVD link : CVE-2025-22129
Mitre link : CVE-2025-22129
CVE.ORG link : CVE-2025-22129
JSON object : View
Products Affected
enalean
- tuleap
CWE
CWE-280
Improper Handling of Insufficient Permissions or Privileges