CVE-2025-30209

Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker can access release notes content or information via the FRS REST endpoints it should not have access to. This vulnerability is fixed in Tuleap Community Edition 16.5.99.1742812323 and Tuleap Enterprise Edition 16.5-6 and 16.4-10.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*

History

21 Aug 2025, 21:59

Type Values Removed Values Added
CPE cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:*
First Time Enalean
Enalean tuleap
References () https://github.com/Enalean/tuleap/commit/34af2d5d10b0349967129f53427f495815e5bbcc - () https://github.com/Enalean/tuleap/commit/34af2d5d10b0349967129f53427f495815e5bbcc - Patch
References () https://github.com/Enalean/tuleap/security/advisories/GHSA-hcp5-pmpm-mgwh - () https://github.com/Enalean/tuleap/security/advisories/GHSA-hcp5-pmpm-mgwh - Third Party Advisory
References () https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=34af2d5d10b0349967129f53427f495815e5bbcc - () https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=34af2d5d10b0349967129f53427f495815e5bbcc - Broken Link
References () https://tuleap.net/plugins/tracker/?aid=42251 - () https://tuleap.net/plugins/tracker/?aid=42251 - Vendor Advisory
Summary
  • (es) Tuleap es una suite de código abierto que mejora la gestión del desarrollo de software y la colaboración. Un atacante puede acceder al contenido o la información de las notas de la versión a través de los endpoints REST de FRS a los que no debería tener acceso. Esta vulnerabilidad está corregida en Tuleap Community Edition 16.5.99.1742812323 y Tuleap Enterprise Edition 16.5-6 y 16.4-10.

31 Mar 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-31 16:15

Updated : 2025-08-21 21:59


NVD link : CVE-2025-30209

Mitre link : CVE-2025-30209

CVE.ORG link : CVE-2025-30209


JSON object : View

Products Affected

enalean

  • tuleap
CWE
CWE-863

Incorrect Authorization