CNNVD-202506-3174 Information

CNNVD ID

CNNVD-202506-3174

CVE-2025-50179

  • CNNVD Published: 2025-06-25

Description (Chinese)

Tuleap是Enalean开源的一个开源套件,旨在改善软件开发和协作的管理。 Tuleap存在跨站请求伪造漏洞,该漏洞源于跨站请求伪造漏洞,可能导致更改预设响应。

Description (English)

Tuleap is an open source package of the Enalean Open Source to improve software development and collaborative management. There is a false gap in cross-site requests in Tuleap, which originates from cross-site requests for forgery, which may lead to changes in preset responses.

Hazard Level

High

Vulnerability Type

跨站请求伪造

Affected Vendor

Enalean

Published

2025-06-25

Last Modified

2026-02-24

References

https://github.com/Enalean/tuleap/security/advisories/GHSA-rxpm-g7gw-4mrv https://tuleap.net/plugins/tracker/?aid=43357 https://github.com/Enalean/tuleap/commit/0f9aab6e3640e892c74c9dfc90ad65fd3aff499e https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=0f9aab6e3640e892c74c9dfc90ad65fd3aff499e https://nvd.nist.gov/vuln/detail/CVE-2025-50179

Patch

https://github.com/Enalean/tuleap/tags

Share on: