We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-53902

Tuleap exposes artifacts to a mentioned user via email notifications



Description

Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition prior to version 16.9.99.1752585665 and Tuleap Enterprise Edition prior to 16.8-6 and 16.9-5, users may potentially access confidential information from artifacts that they are not authorized to view. This is fixed in Tuleap Community Edition prior to version 16.9.99.1752585665 and Tuleap Enterprise Edition prior to 16.8-6 and 16.9-5.

Reserved 2025-07-11 | Published 2025-07-29 | Updated 2025-07-29 | Assigner GitHub_M


MEDIUM: 4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Problem types

CWE-863: Incorrect Authorization

Product status

Tuleap Community Edition < 16.9.99.1752585665
affected

Tuleap Enterprise Edition < 16.8-6
affected

Tuleap Enterprise Edition >= 16.9, < 16.9-5
affected

References

github.com/...tuleap/security/advisories/GHSA-6f24-5v47-rj6j

github.com/...ommit/ebe054df8a2672afee41af84e5ba14b57ef8b789

tuleap.net/...mit&h=ebe054df8a2672afee41af84e5ba14b57ef8b789

tuleap.net/plugins/tracker/?aid=43704

cve.org (CVE-2025-53902)

nvd.nist.gov (CVE-2025-53902)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-53902

Support options

Helpdesk Chat, Email, Knowledgebase