Tuleap is an Open Source Suite to improve management of software developments and collaboration. Backlog item representations do not verify the permissions of the child trackers. Users might see tracker names they should not have access to. This vulnerability is fixed in Tuleap Community Edition 16.11.99.1757427600 and Tuleap Enterprise Edition 16.11-6 and 16.10-8.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 18 Sep 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Backlog item representations do not verify the permissions of the child trackers. Users might see tracker names they should not have access to. This vulnerability is fixed in Tuleap Community Edition 16.11.99.1757427600 and Tuleap Enterprise Edition 16.11-6 and 16.10-8. | |
Title | Tuleap backlog item representations do not verify the permissions of the child trackers | |
Weaknesses | CWE-280 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-09-18T14:28:41.999Z
Reserved: 2025-09-08T16:19:26.171Z
Link: CVE-2025-59040

No data.

Status : Received
Published: 2025-09-18T15:15:38.370
Modified: 2025-09-18T15:15:38.370
Link: CVE-2025-59040

No data.

No data.