Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition versions before 16.10.99.1754050155 and Tuleap Enterprise Edition versions before 16.9-8 and before 16.10-5, an attacker can access to the content of the special and always there fields of accessible artifacts even if the permissions associated with the underlying fields do not allow it. This issue has been fixed in Tuleap Community Edition version 16.10.99.1754050155 and Tuleap Enterprise Edition versions 16.9-8 and 16.10-5.
History

Wed, 03 Sep 2025 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*

Sun, 31 Aug 2025 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Enalean
Enalean tuleap
Vendors & Products Enalean
Enalean tuleap

Fri, 29 Aug 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 29 Aug 2025 15:30:00 +0000

Type Values Removed Values Added
Description Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition versions before 16.10.99.1754050155 and Tuleap Enterprise Edition versions before 16.9-8 and before 16.10-5, an attacker can access to the content of the special and always there fields of accessible artifacts even if the permissions associated with the underlying fields do not allow it. This issue has been fixed in Tuleap Community Edition version 16.10.99.1754050155 and Tuleap Enterprise Edition versions 16.9-8 and 16.10-5.
Title Tuleap's special and always there fields permissions are not verified in cross-tracker search
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-08-29T15:07:54.950Z

Updated: 2025-08-29T15:23:44.584Z

Reserved: 2025-07-31T17:23:33.475Z

Link: CVE-2025-54877

cve-icon Vulnrichment

Updated: 2025-08-29T15:23:35.558Z

cve-icon NVD

Status : Analyzed

Published: 2025-08-29T16:15:36.457

Modified: 2025-09-03T16:09:44.927

Link: CVE-2025-54877

cve-icon Redhat

No data.