Improper Access Control in Tuleap Open Source Suite
CVE-2025-30155
4.3MEDIUM
What is CVE-2025-30155?
The Tuleap Open Source Suite contains an improper access control vulnerability that affects the REST API. Specifically, it fails to properly enforce read permissions on parent trackers, allowing unauthorized access to potentially sensitive information. This security issue has been addressed in the latest updates for both the Community and Enterprise editions, ensuring that user permissions are correctly enforced and safeguarding project data.
Affected Version(s)
tuleap < 16.5.99.1742392651