PT-2025-46700 · Unknown · Tuleap Community Edition+2

Published

2025-11-12

·

Updated

2025-11-12

·

CVE-2025-64117

CVSS v3.1

4.6

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Tuleap Community Edition versions prior to 16.13.99.1761813675 Tuleap Enterprise Edition versions prior to 16.13-5 and 16.12-8
Description Tuleap lacks cross-site request forgery (CSRF) protection in the management of Subversion (SVN) commit rules and immutable tags. An attacker could exploit this to trick users into modifying the commit rules or immutable tags of an SVN repository. Cross-site request forgery is a type of web security flaw that allows an attacker to induce a user to perform actions on a web application in which they are currently authenticated.
Recommendations Tuleap Community Edition versions prior to 16.13.99.1761813675 should be updated to version 16.13.99.1761813675 or later. Tuleap Enterprise Edition versions prior to 16.13-5 should be updated to version 16.13-5 or later. Tuleap Enterprise Edition versions prior to 16.12-8 should be updated to version 16.12-8 or later.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-64117
GHSA-P2F7-QW8P-F2P7

Affected Products

Subversion
Tuleap Community Edition
Tuleap Enterprise Edition