CNNVD-202507-3659 Information

CNNVD ID

CNNVD-202507-3659

CVE-2025-53902

  • CNNVD Published: 2025-07-29

Description (Chinese)

Enalean Tuleap Community Edition和Enalean Tuleap Enterprise Edition都是Enalean开源的一个开源套件,旨在改善软件开发和协作的管理。 Enalean Tuleap Community Edition 16.9.99.1752585665之前版本和Enalean Tuleap Enterprise Edition 16.8-6和16.9-5之前版本存在安全漏洞,该漏洞源于用户可能访问未授权查看的机密信息。

Description (English)

Enalean Tuleap Community Edition and Enalean Tuleap Enterprise Edition are open-source packages from the Enalean Open Source to improve software development and collaborative management. There is a security loophole in the pre-Enalean Tuleap Commission 16.9.99.1752585665 and the pre-Enalean Tuleap Enterprise 16.8-6 and 16.9-5 versions, which stems from the possibility of users accessing unauthorised confidential information.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

Enalean

Published

2025-07-29

Last Modified

2026-02-24

References

https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=ebe054df8a2672afee41af84e5ba14b57ef8b789 https://tuleap.net/plugins/tracker/?aid=43704 https://github.com/Enalean/tuleap/security/advisories/GHSA-6f24-5v47-rj6j https://github.com/Enalean/tuleap/commit/ebe054df8a2672afee41af84e5ba14b57ef8b789 https://nvd.nist.gov/vuln/detail/CVE-2025-53902

Patch

https://github.com/Enalean/tuleap/tags

Share on: