CSRF Vulnerability in Tuleap Planning Management API
CVE-2025-64499
What is CVE-2025-64499?
Tuleap, an open-source software development and collaboration suite, is susceptible to Cross-Site Request Forgery (CSRF) attacks through its planning management API. Unsanctioned actors can potentially create, edit, or delete planning plans without proper authorization. This security issue affects specific versions of Tuleap, prompting the need for immediate updates to the fixed versions to safeguard against any unauthorized manipulation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
tuleap Tuleap Community Edition < 17.0.99.1762456922 < Tuleap Community Edition 17.0.99.1762456922
tuleap Tuleap Enterprise Edition < 17.0-2 < Tuleap Enterprise Edition 17.0-2
tuleap Tuleap Enterprise Edition < 16.13-7 < Tuleap Enterprise Edition 16.13-7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
