Access Control Weakness in Tuleap Open Source Suite by Enalean
CVE-2025-54877

5.3MEDIUM

Key Information:

Vendor

Enalean

Status
Vendor
CVE Published:
29 August 2025

What is CVE-2025-54877?

In Tuleap, an open-source suite for software development management, an access control vulnerability exists that allows attackers to view sensitive content in artifacts regardless of their permission settings. This issue occurs in Tuleap Community Edition and Enterprise Edition versions prior to specific updates, and it has been addressed in the latest releases, enhancing the security of artifact management.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

tuleap Tuleap Community Edition < 16.10.99.1754050155 < Tuleap Community Edition 16.10.99.1754050155

tuleap Tuleap Enterprise Edition < 16.10-5 < Tuleap Enterprise Edition 16.10-5

tuleap Tuleap Enterprise Edition < 16.9-8 < Tuleap Enterprise Edition 16.9-8

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.