PT-2025-46700 · Unknown · Tuleap Community Edition+2

CVE-2025-64117

·

Publicado

2025-11-12

·

Atualizado

2025-11-12

CVSS v3.1

4.6

Média

VetorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Tuleap Community Edition versions prior to 16.13.99.1761813675 Tuleap Enterprise Edition versions prior to 16.13-5 and 16.12-8
Description Tuleap lacks cross-site request forgery (CSRF) protection in the management of Subversion (SVN) commit rules and immutable tags. An attacker could exploit this to trick users into modifying the commit rules or immutable tags of an SVN repository. Cross-site request forgery is a type of web security flaw that allows an attacker to induce a user to perform actions on a web application in which they are currently authenticated.
Recommendations Tuleap Community Edition versions prior to 16.13.99.1761813675 should be updated to version 16.13.99.1761813675 or later. Tuleap Enterprise Edition versions prior to 16.13-5 should be updated to version 16.13-5 or later. Tuleap Enterprise Edition versions prior to 16.12-8 should be updated to version 16.12-8 or later.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-64117
GHSA-P2F7-QW8P-F2P7

Produtos afetados

Subversion
Tuleap Community Edition
Tuleap Enterprise Edition