CNNVD-202506-3154 Information
CNNVD ID
CNNVD-202506-3154
Related CVE
- CNNVD Published: 2025-06-25
Description (Chinese)
Tuleap是Enalean开源的一个开源套件,旨在改善软件开发和协作的管理。 Tuleap存在跨站请求伪造漏洞,该漏洞源于可能诱骗受害者更改预设响应。
Description (English)
Tuleap is an open source package of the Enalean Open Source to improve software development and collaborative management. Tuleap had a cross-site request to forge a loophole, which stemmed from a pre-set response that might induce victims to change.
Hazard Level
High
Vulnerability Type
跨站请求伪造
Affected Vendor
Enalean
Published
2025-06-25
Last Modified
2026-02-24
References
https://github.com/Enalean/tuleap/commit/cbf9b2a38e33dfd755dc2ccf074126b598a78274 https://github.com/Enalean/tuleap/security/advisories/GHSA-px9r-875r-w534 https://tuleap.net/plugins/tracker/?aid=43326 https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=cbf9b2a38e33dfd755dc2ccf074126b598a78274 https://nvd.nist.gov/vuln/detail/CVE-2025-48991
Patch
https://github.com/Enalean/tuleap/tags
Share on: