Tuleap's special and always there fields permissions are not verified in cross-tracker search
Published Aug 29, 2025
5.3
MEDIUMCVSS 3.1
EPSS 0.29%
Description
Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition versions before 16.10.99.1754050155 and Tuleap Enterprise Edition versions before 16.9-8 and before 16.10-5, an attacker can access to the content of the special and always there fields of accessible artifacts even if the permissions associated with the underlying fields do not allow it. This issue has been fixed in Tuleap Community Edition version 16.10.99.1754050155 and Tuleap Enterprise Edition versions 16.9-8 and 16.10-5.
Affected products
-
- Version Tuleap Community Edition < 16.10.99.1754050155StatusaffectedConstraints-
- Version Tuleap Enterprise Edition < 16.10-5StatusaffectedConstraints-
- Version Tuleap Enterprise Edition < 16.9-8StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-28572 Advisory
- https://github.com/Enalean/tuleap/commit/b0c1328f96135ee6a3f84d0847be5f843eafa590 x_refsource_MISCPatch
- https://github.com/Enalean/tuleap/security/advisories/GHSA-m5qc-c3q5-2p29 x_refsource_CONFIRMThird Party Advisory
- https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=b0c1328f96135ee6a3f84d0847be5f843eafa590 x_refsource_MISCBroken Link
- https://tuleap.net/plugins/tracker/?aid=44068 x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-28572 | Advisory | |
| https://github.com/Enalean/tuleap/commit/b0c1328f96135ee6a3f84d0847be5f843eafa590 | x_refsource_MISCPatch | |
| https://github.com/Enalean/tuleap/security/advisories/GHSA-m5qc-c3q5-2p29 | x_refsource_CONFIRMThird Party Advisory | |
| https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=b0c1328f96135ee6a3f84d0847be5f843eafa590 | x_refsource_MISCBroken Link | |
| https://tuleap.net/plugins/tracker/?aid=44068 | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.