Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition prior to version 16.9.99.1752585665 and Tuleap Enterprise Edition prior to 16.8-6 and 16.9-5, users may potentially access confidential information from artifacts that they are not authorized to view. This is fixed in Tuleap Community Edition prior to version 16.9.99.1752585665 and Tuleap Enterprise Edition prior to 16.8-6 and 16.9-5.
History

Wed, 30 Jul 2025 06:30:00 +0000

Type Values Removed Values Added
First Time appeared Enalean
Enalean tuleap
Vendors & Products Enalean
Enalean tuleap

Tue, 29 Jul 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Jul 2025 19:45:00 +0000

Type Values Removed Values Added
Description Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition prior to version 16.9.99.1752585665 and Tuleap Enterprise Edition prior to 16.8-6 and 16.9-5, users may potentially access confidential information from artifacts that they are not authorized to view. This is fixed in Tuleap Community Edition prior to version 16.9.99.1752585665 and Tuleap Enterprise Edition prior to 16.8-6 and 16.9-5.
Title Tuleap exposes artifacts to a mentioned user via email notifications
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-07-29T19:36:10.910Z

Updated: 2025-07-29T19:41:49.056Z

Reserved: 2025-07-11T19:05:23.826Z

Link: CVE-2025-53902

cve-icon Vulnrichment

Updated: 2025-07-29T19:41:41.301Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-29T20:15:28.673

Modified: 2025-07-31T18:42:56.503

Link: CVE-2025-53902

cve-icon Redhat

No data.