CVE-2025-53902
Last modified
CVE-2025-53902 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition prior to version 16.9.99.1752585665 and Tuleap Enterprise Edition prior to 16.8-6 and 16.9-5, users may potentially access confidential information from artifacts that they are not authorized to view. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition prior to version 16.9.99.1752585665 and Tuleap Enterprise Edition prior to 16.8-6 and 16.9-5, users may potentially access confidential information from artifacts that they are not authorized to view. This is fixed in Tuleap Community Edition prior to version 16.9.99.1752585665 and Tuleap Enterprise Edition prior to 16.8-6 and 16.9-5.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Enalean | Tuleap | < 16.8-6 |
| Enalean | Tuleap | < 16.9.99.1752585665 |
| Enalean | Tuleap | >= 16.9, < 16.9-5 |
References
- https://github.com/Enalean/tuleap/security/advisories/GHSA-6f24-5v47-rj6jThird Party Advisory
- https://tuleap.net/plugins/tracker/?aid=43704Exploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-53902?
How severe is CVE-2025-53902?
How do I fix CVE-2025-53902?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-53896Kiteworks MFT orchestrates end-to-end file transfer workflow…8.1
- CVE-2025-53897Kiteworks MFT orchestrates end-to-end file transfer workflow…6.8
- CVE-2025-53899Kiteworks MFT orchestrates end-to-end file transfer workflow…7.2
- CVE-2025-5390A vulnerability, which was classified as critical, was found…9.8
- CVE-2025-53900Kiteworks MFT orchestrates end-to-end file transfer workflow…8.8
- CVE-2025-53901Wasmtime is a runtime for WebAssembly. Prior to versions 24.…3.5
- CVE-2025-53903The Scratch Channel is a news website that is under developm…1.3
- CVE-2025-53904The Scratch Channel is a news website that is under developm…1.3
- CVE-2025-53905Vim is an open source, command line text editor. Prior to ve…4.1
- CVE-2025-53906Vim is an open source, command line text editor. Prior to ve…4.1
- CVE-2025-53908RomM is a self-hosted rom manager and player. Versions prior…8.3
- CVE-2025-53909mailcow: dockerized is an open source groupware/email suite …7.2
Are you affected by CVE-2025-53902?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
