PT-2025-9509 · Unknown · Tuleap Enterprise Edition+1

Marie Ange Garnier

+1

·

Published

2025-03-03

·

Updated

2025-07-10

·

CVE-2025-27094

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Tuleap Community Edition versions 16.4.99.1739806825 through 16.4.99.1739877910 Tuleap Enterprise Edition versions prior to 16.3-9 Tuleap Enterprise Edition versions prior to 16.4-4
Description A malicious user with access to a tracker could force-reset certain field configurations, leading to potential information loss. The display time attribute for the date field, the size attribute for the multiselectbox field, the default value, number of rows, and columns attributes for the text field, and the default value, size, and max characters attributes for the string field configurations are lost when added as criteria in a saved report. This issue could be exploited to prevent access to tracker data by triggering a crash.
Recommendations For Tuleap Community Edition versions 16.4.99.1739806825 through 16.4.99.1739877910, update to version 16.4.99.1739877910 or later. For Tuleap Enterprise Edition versions prior to 16.3-9, update to version 16.3-9 or later. For Tuleap Enterprise Edition versions prior to 16.4-4, update to version 16.4-4 or later. As a temporary workaround, consider restricting access to the tracker to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-27094
GHSA-R85G-9WJX-PW7F

Affected Products

Tuleap Community Edition
Tuleap Enterprise Edition