CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-22129: Initial effort field does not respect field permissions in the Taskboard REST card representation in Tuleap

4.3 CVSS

Description

Tuleap is an Open Source Suite to improve management of software developments and collaboration. In affected versions an unauthorized user might get access to restricted information. This issue has been addressed in Tuleap Community Edition 16.3.99.1736242932, Tuleap Enterprise Edition 16.2-5, and Tuleap Enterprise Edition 16.3-2. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Classification

CVE ID: CVE-2025-22129

CVSS Base Severity: MEDIUM

CVSS Base Score: 4.3

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Affected Products

Vendor: Enalean

Product: tuleap

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 18.32% (scored less or equal to compared to others)

EPSS Date: 2025-03-04 (when was this score calculated)

References

https://github.com/Enalean/tuleap/security/advisories/GHSA-f34g-wc2m-mf76
https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=3edf8158ba40be66f0b661888b8b2805784795d1
https://tuleap.net/plugins/tracker/?aid=41434

Timeline