Unauthorized Access in Tuleap Open Source Suite
CVE-2025-30209

5.3MEDIUM

Key Information:

Vendor

Enalean

Status
Vendor
CVE Published:
31 March 2025

What is CVE-2025-30209?

A vulnerability in the Tuleap Open Source Suite allows attackers to gain unauthorized access to sensitive release notes content via the FRS REST endpoints. This flaw compromises the integrity of information management within the software development lifecycle by exposing data that should remain confidential. It has been addressed in the latest updates, urging users to upgrade to Tuleap Community Edition 16.5.99.1742812323 or Tuleap Enterprise Edition 16.5-6 and 16.4-10.

Affected Version(s)

tuleap < 16.5.99.1742812323

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.