PT-2025-46700 · Unknown · Tuleap Community Edition+2
Published
2025-11-12
·
Updated
2025-11-12
·
CVE-2025-64117
CVSS v3.1
4.6
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Tuleap Community Edition versions prior to 16.13.99.1761813675
Tuleap Enterprise Edition versions prior to 16.13-5 and 16.12-8
Description
Tuleap lacks cross-site request forgery (CSRF) protection in the management of Subversion (SVN) commit rules and immutable tags. An attacker could exploit this to trick users into modifying the commit rules or immutable tags of an SVN repository. Cross-site request forgery is a type of web security flaw that allows an attacker to induce a user to perform actions on a web application in which they are currently authenticated.
Recommendations
Tuleap Community Edition versions prior to 16.13.99.1761813675 should be updated to version 16.13.99.1761813675 or later.
Tuleap Enterprise Edition versions prior to 16.13-5 should be updated to version 16.13-5 or later.
Tuleap Enterprise Edition versions prior to 16.12-8 should be updated to version 16.12-8 or later.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Subversion
Tuleap Community Edition
Tuleap Enterprise Edition