VYPR

Tuleap

by Tuleap

CVEs (24)

  • CVE-2021-43806HigDec 15, 2021
    risk 0.57cvss 8.8epss 0.02

    Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. In affected versions Tuleap does not sanitize properly user settings when constructing the SQL query to browse and search commits in the CVS repositories. A authenticated…

  • CVE-2021-41155HigOct 18, 2021
    risk 0.57cvss 8.8epss 0.02

    Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versions Tuleap does not sanitize properly user inputs when constructing the SQL query to browse and search revisions in the CVS repositories. The following…

  • CVE-2021-41154HigOct 18, 2021
    risk 0.57cvss 8.8epss 0.02

    Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versions an attacker with read access to a "SVN core" repository could execute arbitrary SQL queries. The following versions contain the fix: Tuleap Community…

  • CVE-2021-43782MedDec 15, 2021
    risk 0.44cvss 6.7epss 0.01

    Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. This is a follow up to GHSA-887w-pv2r-x8pm/CVE-2021-41276, the initial fix was incomplete. Tuleap does not sanitize properly the search filter built from the ldap_id…

  • CVE-2021-41276MedDec 15, 2021
    risk 0.44cvss 6.7epss 0.01

    Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. In affected versions Tuleap does not sanitize properly the search filter built from the ldap_id attribute of a user during the daily synchronization. A malicious user could…

  • CVE-2023-38508MedAug 24, 2023
    risk 0.42cvss 6.5epss 0.01

    Tuleap is an open source suite to improve management of software developments and collaboration. In Tuleap Community Edition prior to version 14.11.99.28 and Tuleap Enterprise Edition prior to versions 14.10-6 and 14.11-3, the preview of an artifact link with a type does not…

  • CVE-2025-27094MedMar 3, 2025
    risk 0.35cvss 5.4epss 0.00

    Tuleap is an open-source suite designed to improve software development management and collaboration. A malicious user with access to a tracker could force-reset certain field configurations, leading to potential information loss. The display time attribute for the date field,…

  • CVE-2024-52599MedDec 9, 2024
    risk 0.35cvss 5.4epss 0.00

    Tuleap is an open source suite to improve management of software developments and collaboration. In Tuleap Community Edition prior to version 16.1.99.50 and Tuleap Enterprise Edition prior to versions 16.1-4 and 16.0-7, a malicious user with the ability to create an artifact in…

  • CVE-2022-31128MedAug 1, 2022
    risk 0.35cvss 5.4epss 0.01

    Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versions Tuleap does not properly verify permissions when creating branches with the REST API in Git repositories using the fine grained permissions. Users can…

  • CVE-2025-30209MedMar 31, 2025
    risk 0.34cvss 5.3epss 0.00

    Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker can access release notes content or information via the FRS REST endpoints it should not have access to. This vulnerability is fixed in Tuleap Community Edition…

  • CVE-2025-24029MedFeb 3, 2025
    risk 0.34cvss 5.3epss 0.00

    Tuleap is an Open Source Suite to improve management of software developments and collaboration. Users (possibly anonymous ones if the widget is used in the dashboard of a public project) might get access to artifacts they should not see. This issue has been addressed in Tuleap…

  • CVE-2024-46988MedOct 14, 2024
    risk 0.31cvss 4.8epss 0.00

    Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.40, Tuleap Enterprise Edition 15.13-3, and Tuleap Enterprise Edition 15.12-6, users might receive email notification with information they should not…

  • CVE-2024-46980MedOct 14, 2024
    risk 0.31cvss 4.8epss 0.00

    Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.37, Tuleap Enterprise Edition 15.13-3, and Tuleap Enterprise Edition 15.12-6, a site administrator could create an artifact link type with a forward…

  • CVE-2023-39521MedAug 24, 2023
    risk 0.31cvss 4.8epss 0.00

    Tuleap is an open source suite to improve management of software developments and collaboration. In Tuleap Community Edition prior to version 14.11.99.28 and Tuleap Enterprise Edition prior to versions 14.10-6 and 14.11-3, content displayed in the "card fields" (visible in the…

  • CVE-2026-24007MedFeb 2, 2026
    risk 0.30cvss 4.6epss 0.00

    Tuleap is an Open Source Suite for management of software development and collaboration. Tuleap is missing CSRF protection in the Overview inconsistent items. An attacker could use this vulnerability to trick victims into repairing inconsistent items (creating artifact links…

  • CVE-2025-50179MedJun 25, 2025
    risk 0.30cvss 4.6epss 0.00

    Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker could use a cross-site request forgery vulnerability in Tuleap Community Edition prior to version 16.8.99.1749830289 and Tuleap Enterprise Edition prior to version 16.9-1…

  • CVE-2025-29766MedMar 31, 2025
    risk 0.30cvss 4.6epss 0.00

    Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap has missing CSRF protections on artifact submission & edition from the tracker view. An attacker could use this vulnerability to trick victims into submitting or editing…

  • CVE-2025-27401MedMar 4, 2025
    risk 0.30cvss 4.6epss 0.00

    Tuleap is an Open Source Suite to improve management of software developments and collaboration. In a standard usages of Tuleap, the issue has a limited impact, it will mostly leave dangling data. However, a malicious user could create and delete reports multiple times to cycle…

  • CVE-2025-22129MedFeb 3, 2025
    risk 0.28cvss 4.3epss 0.00

    Tuleap is an Open Source Suite to improve management of software developments and collaboration. In affected versions an unauthorized user might get access to restricted information. This issue has been addressed in Tuleap Community Edition 16.3.99.1736242932, Tuleap Enterprise…

  • CVE-2022-46160MedDec 13, 2022
    risk 0.28cvss 4.3epss 0.01

    Tuleap is an Open Source Suite to improve management of software developments and collaboration. In versions prior to 14.2.99.104, project level authorizations are not properly verified when accessing the project "homepage"/dashboards. Users not authorized to access a project…

Page 1 of 2