CVE Explorer
CVE-2025-64117
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap Community Edition prior to version 16.13.99.1761813675 and Tuleap Enterprise Edition prior to versions 16.13-5 and 16.12-8 don't have cross-site request forgery protection in the management of SVN commit rules and immutable tags. An attacker could use this vulnerability to trick victims into changing the commit rules or immutable tags of a SVN repo. Tuleap Community Edition 16.13.99.1761813675
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"tuleap","vendor":"Enalean","versions":[{"status":"affected","version":"Tuleap Community Edition < 16.13.99.1761813675"},{"status":"affected","version":"Tuleap Enterprise Edition < 16.13-5"},{"status":"affected","version":"Tuleap Enterprise Edition < 16.12-8"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:ec075ea56ee3c5922ea0df2fe228fdd8c831b1b5393d55f91ac6daba2e7836e7 · sha256:b5a6f798b5a7c3bb… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":4.6,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:ec075ea56ee3c5922ea0df2fe228fdd8c831b1b5393d55f91ac6daba2e7836e7 · sha256:b5a6f798b5a7c3bb… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-352","description":"CWE-352: Cross-Site Request Forgery (CSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:ec075ea56ee3c5922ea0df2fe228fdd8c831b1b5393d55f91ac6daba2e7836e7 · sha256:b5a6f798b5a7c3bb… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"name":"https://github.com/Enalean/tuleap/commit/f49419f63edbbaa31ce8417b737431d944827404","tags":["x_refsource_MISC"],"url":"https://github.com/Enalean/tuleap/commit/f49419f63edbbaa31ce8417b737431d944827404"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ec075ea56ee3c5922ea0df2fe228fdd8c831b1b5393d55f91ac6daba2e7836e7 · sha256:b5a6f798b5a7c3bb… · /containers/cna/references/1
{"name":"https://github.com/Enalean/tuleap/security/advisories/GHSA-p2f7-qw8p-f2p7","tags":["x_refsource_CONFIRM"],"url":"https://github.com/Enalean/tuleap/security/advisories/GHSA-p2f7-qw8p-f2p7"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ec075ea56ee3c5922ea0df2fe228fdd8c831b1b5393d55f91ac6daba2e7836e7 · sha256:b5a6f798b5a7c3bb… · /containers/cna/references/0
{"name":"https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=f49419f63edbbaa31ce8417b737431d944827404","tags":["x_refsource_MISC"],"url":"https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=f49419f63edbbaa31ce8417b737431d944827404"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ec075ea56ee3c5922ea0df2fe228fdd8c831b1b5393d55f91ac6daba2e7836e7 · sha256:b5a6f798b5a7c3bb… · /containers/cna/references/2
{"name":"https://tuleap.net/plugins/tracker/?aid=45251","tags":["x_refsource_MISC"],"url":"https://tuleap.net/plugins/tracker/?aid=45251"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ec075ea56ee3c5922ea0df2fe228fdd8c831b1b5393d55f91ac6daba2e7836e7 · sha256:b5a6f798b5a7c3bb… · /containers/cna/references/3
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.