CSRF Vulnerability in Tuleap Planning Management API
CVE-2025-64499
4.6MEDIUM
What is CVE-2025-64499?
Tuleap, an open-source software development and collaboration suite, is susceptible to Cross-Site Request Forgery (CSRF) attacks through its planning management API. Unsanctioned actors can potentially create, edit, or delete planning plans without proper authorization. This security issue affects specific versions of Tuleap, prompting the need for immediate updates to the fixed versions to safeguard against any unauthorized manipulation.
Affected Version(s)
tuleap Tuleap Community Edition < 17.0.99.1762456922 < Tuleap Community Edition 17.0.99.1762456922
tuleap Tuleap Enterprise Edition < 17.0-2 < Tuleap Enterprise Edition 17.0-2
tuleap Tuleap Enterprise Edition < 16.13-7 < Tuleap Enterprise Edition 16.13-7
