Access Control Weakness in Tuleap Open Source Suite by Enalean
CVE-2025-54877
What is CVE-2025-54877?
In Tuleap, an open-source suite for software development management, an access control vulnerability exists that allows attackers to view sensitive content in artifacts regardless of their permission settings. This issue occurs in Tuleap Community Edition and Enterprise Edition versions prior to specific updates, and it has been addressed in the latest releases, enhancing the security of artifact management.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
tuleap Tuleap Community Edition < 16.10.99.1754050155 < Tuleap Community Edition 16.10.99.1754050155
tuleap Tuleap Enterprise Edition < 16.10-5 < Tuleap Enterprise Edition 16.10-5
tuleap Tuleap Enterprise Edition < 16.9-8 < Tuleap Enterprise Edition 16.9-8
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
