PT-2025-9509 · Unknown · Tuleap Enterprise Edition+1
Marie Ange Garnier
+1
·
Published
2025-03-03
·
Updated
2025-07-10
·
CVE-2025-27094
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Tuleap Community Edition versions 16.4.99.1739806825 through 16.4.99.1739877910
Tuleap Enterprise Edition versions prior to 16.3-9
Tuleap Enterprise Edition versions prior to 16.4-4
Description
A malicious user with access to a tracker could force-reset certain field configurations, leading to potential information loss. The display time attribute for the
date field, the size attribute for the multiselectbox field, the default value, number of rows, and columns attributes for the text field, and the default value, size, and max characters attributes for the string field configurations are lost when added as criteria in a saved report. This issue could be exploited to prevent access to tracker data by triggering a crash.Recommendations
For Tuleap Community Edition versions 16.4.99.1739806825 through 16.4.99.1739877910, update to version 16.4.99.1739877910 or later.
For Tuleap Enterprise Edition versions prior to 16.3-9, update to version 16.3-9 or later.
For Tuleap Enterprise Edition versions prior to 16.4-4, update to version 16.4-4 or later.
As a temporary workaround, consider restricting access to the tracker to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tuleap Community Edition
Tuleap Enterprise Edition