Settings Change Vulnerability in Tuleap Open Source Suite
CVE-2025-64498

4.6MEDIUM

Key Information:

Vendor

Enalean

Status
Vendor
CVE Published:
8 December 2025

What is CVE-2025-64498?

Tuleap, an open-source suite designed for software development and collaboration, is affected by a vulnerability that allows attackers to manipulate general settings within trackers. This issue impacts versions of the Tuleap Community Edition below 17.0.99.1762444754 and multiple versions of the Tuleap Enterprise Edition prior to specific releases. Users should upgrade to the latest versions to mitigate potential exploitation risks.

Affected Version(s)

tuleap Tuleap Community Edition < 17.0.99.1762444754 < Tuleap Community Edition 17.0.99.1762444754

tuleap Tuleap Enterprise Edition < 17.0-2 < Tuleap Enterprise Edition 17.0-2

tuleap Tuleap Enterprise Edition < 16.13-7 < Tuleap Enterprise Edition 16.13-7

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-64498 : Settings Change Vulnerability in Tuleap Open Source Suite