Tuleap is an Open Source Suite to improve management of software developments and collaboration. In affected versions an unauthorized user might get access to restricted information. This issue has been addressed in Tuleap Community Edition 16.3.99.1736242932, Tuleap Enterprise Edition 16.2-5, and Tuleap Enterprise Edition 16.3-2. Users are advised to upgrade. There are no known workarounds for this vulnerability.
History

Tue, 04 Feb 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Feb 2025 21:45:00 +0000

Type Values Removed Values Added
Description Tuleap is an Open Source Suite to improve management of software developments and collaboration. In affected versions an unauthorized user might get access to restricted information. This issue has been addressed in Tuleap Community Edition 16.3.99.1736242932, Tuleap Enterprise Edition 16.2-5, and Tuleap Enterprise Edition 16.3-2. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Title Initial effort field does not respect field permissions in the Taskboard REST card representation in Tuleap
Weaknesses CWE-280
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-02-04T18:41:39.965Z

Reserved: 2024-12-30T03:00:33.651Z

Link: CVE-2025-22129

cve-icon Vulnrichment

Updated: 2025-02-04T18:40:29.859Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-02-03T22:15:28.040

Modified: 2025-02-04T19:15:33.360

Link: CVE-2025-22129

cve-icon Redhat

No data.