CVE-2025-65962

Tuleap is a free and open source suite for management of software development and collaboration. Versions of Tuleap Community Edition prior to 17.0.99.1763803709 and Tuleap Enterprise Edition versions prior to 17.0-4 and 16.13-9 are mission CSRF protections in its tracker field dependencies, allowing attackers to modify tracker fields. This issue is fixed in Tuleap Community Edition version 17.0.99.1763803709 and Tuleap Enterprise Edition versions 17.0-4 and 16.13-9.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*

History

10 Dec 2025, 23:49

Type Values Removed Values Added
First Time Enalean
Enalean tuleap
CPE cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:*
References () https://github.com/Enalean/tuleap/commit/26678c5b411042e68964b199bf88a44607550633 - () https://github.com/Enalean/tuleap/commit/26678c5b411042e68964b199bf88a44607550633 - Patch
References () https://github.com/Enalean/tuleap/security/advisories/GHSA-9hgc-cm68-rrgc - () https://github.com/Enalean/tuleap/security/advisories/GHSA-9hgc-cm68-rrgc - Vendor Advisory
References () https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=26678c5b411042e68964b199bf88a44607550633 - () https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=26678c5b411042e68964b199bf88a44607550633 - Patch
References () https://tuleap.net/plugins/tracker/?aid=45632 - () https://tuleap.net/plugins/tracker/?aid=45632 - Issue Tracking, Vendor Advisory

09 Dec 2025, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-09 00:15

Updated : 2025-12-10 23:49


NVD link : CVE-2025-65962

Mitre link : CVE-2025-65962

CVE.ORG link : CVE-2025-65962


JSON object : View

Products Affected

enalean

  • tuleap
CWE
CWE-352

Cross-Site Request Forgery (CSRF)