« Volver al listado

CVE-2025-53902

Estado: AnalizadaMedia (4.3)—

Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition prior to version 16.9.99.1752585665 and Tuleap Enterprise Edition prior to 16.8-6 and 16.9-5, users may potentially access confidential information from artifacts that they are not authorized to view. This is fixed in Tuleap Community Edition prior to version 16.9.99.1752585665 and Tuleap Enterprise Edition prior to 16.8-6 and 16.9-5.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-53902",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-53902",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-07-29T19:41:37.859082Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "Enalean",
          "product": "tuleap",
          "versions": [
            {
              "status": "affected",
              "version": "Tuleap Community Edition < 16.9.99.1752585665"
            },
            {
              "status": "affected",
              "version": "Tuleap Enterprise Edition < 16.8-6"
            },
            {
              "status": "affected",
              "version": "Tuleap Enterprise Edition >= 16.9, < 16.9-5"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-07-29T20:15:28.673",
  "references": [
    {
      "url": "https://github.com/Enalean/tuleap/commit/ebe054df8a2672afee41af84e5ba14b57ef8b789",
      "tags": [
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/Enalean/tuleap/security/advisories/GHSA-6f24-5v47-rj6j",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=ebe054df8a2672afee41af84e5ba14b57ef8b789",
      "tags": [
        "Permissions Required"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://tuleap.net/plugins/tracker/?aid=43704",
      "tags": [
        "Exploit",
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-863"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition prior to version 16.9.99.1752585665 and Tuleap Enterprise Edition prior to 16.8-6 and 16.9-5, users may potentially access confidential information from artifacts that they are not authorized to view. This is fixed in Tuleap Community Edition prior to version 16.9.99.1752585665 and Tuleap Enterprise Edition prior to 16.8-6 and 16.9-5."
    },
    {
      "lang": "es",
      "value": "Tuleap es una suite de código abierto creada para facilitar la gestión del desarrollo de software y la colaboración. En Tuleap Community Edition anterior a la versión 16.9.99.1752585665 y Tuleap Enterprise Edition anterior a la 16.8-6 y 16.9-5, los usuarios podrían acceder a información confidencial de artefactos a los que no están autorizados a acceder. Esto se ha corregido en Tuleap Community Edition anterior a la versión 16.9.99.1752585665 y Tuleap Enterprise Edition anterior a la 16.8-6 y 16.9-5."
    }
  ],
  "lastModified": "2026-06-17T09:39:06.297",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DEC35025-2E64-412A-A4CF-64F2D4FB51CD",
              "versionEndExcluding": "16.8-6"
            },
            {
              "criteria": "cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5B652FD8-9D66-402B-9EC0-4A3509B44322",
              "versionEndExcluding": "16.9.99.1752585665"
            },
            {
              "criteria": "cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ED55BA98-E49B-4E6F-AF9F-2AC22C60D0BD",
              "versionEndExcluding": "16.9-5",
              "versionStartIncluding": "16.9"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}