CVE-2025-64497 - Tuleap exposes releases for all projects to File Release System project administ...

CVE-2025-64497 - Tuleap exposes releases for all projects to File Release System project administ...

CVE ID : CVE-2025-64497 Published : Dec. 8, 2025, 11:15 p.m. | 55 minutes ago Description : Tuleap is an Open Source Suite for management of software development and collaboration. Versions below 17.0.99.1762431347 of Tuleap Community Edition and Tuleap Enterprise Edition below 17.0-2, 16.13-7 and 16.12-10 allow attackers to access file release system information in projects they do not have access to. This issue is fixed in version 17.0.99.1762431347 of the Tuleap Community Edition and versions 17.0-2, 16.13-7 and 16.12-10 of Tuleap Enterprise Edition. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
Dec. 8, 2025

Source: Telegram CVE Monitor