CVE-2025-64482
Last modified
CVE-2025-64482 is a medium-severity vulnerability rated 4.6/10 on the CVSS scale. Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap Community Edition prior to version 16.13.99.1762267347 and Tuleap Enterprise Edition prior to versions 17.01-, 16.13-6, and 16.12-9 don't have cross-site request forgery protections in the file release system. EPSS estimates a 0.12% chance of exploitation in the next 30 days.
Description
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap Community Edition prior to version 16.13.99.1762267347 and Tuleap Enterprise Edition prior to versions 17.01-, 16.13-6, and 16.12-9 don't have cross-site request forgery protections in the file release system. An attacker could use this vulnerability to trick victims into changing the commit rules or immutable tags of a SVN repo. Tuleap Community Edition 16.13.99.1762267347, Tuleap Enterprise Edition 17.0-1, Tuleap Enterprise Edition 16.13-6, and Tuleap Enterprise Edition 16.12-9 fix the issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-64482?
How severe is CVE-2025-64482?
How do I fix CVE-2025-64482?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-64477Rejected reason: Not used
- CVE-2025-64478Rejected reason: Not used
- CVE-2025-64479Rejected reason: Not used
- CVE-2025-6448A vulnerability has been found in code-projects Simple Onlin…9.8
- CVE-2025-64480Rejected reason: Not used
- CVE-2025-64481Datasette is an open source multi-tool for exploring and pub…2.7
- CVE-2025-64483Wazuh is a security detection, visibility, and compliance op…5.3
- CVE-2025-64484OAuth2-Proxy is an open-source tool that can act as either a…8.5
- CVE-2025-64485CVAT is an open source interactive video and image annotatio…5.3
- CVE-2025-64486calibre is an e-book manager. In versions 8.13.0 and prior, …9.3
- CVE-2025-64487Outline is a service that allows for collaborative documenta…7.6
- CVE-2025-64488SuiteCRM is an open-source, enterprise-ready Customer Relati…8.8
Are you affected by CVE-2025-64482?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
