Access Control Issue in Tuleap Open Source Suite by Enalean
CVE-2025-59040
4.3MEDIUM
What is CVE-2025-59040?
Tuleap, an open-source suite designed for managing software development and collaboration, contains an access control vulnerability that allows unauthorized users to view tracker names that they should not have access to. This flaw stems from the improper verification of permissions for child trackers associated with backlog item representations. It is crucial for users of Tuleap to upgrade to the corrected versions to ensure their data and system remain secure.
Affected Version(s)
tuleap < 16.11.99.1757427600
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
