CVE-2025-30155

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Mar 31, 2025
Updated: Apr 1, 2025
CWE ID 863

Summary

CVE-2025-30155 is a vulnerability affecting Tuleap, an open-source software development and collaboration platform. The issue lies in the REST API where read permissions on parent trackers are not enforced. This vulnerability can potentially expose sensitive information to unauthorized users. Tuleap has released patches for this issue in version 16.5.99.1742392651 for the Community Edition and versions 16.5-5 and 16.4-8 for the Enterprise Edition. Users are advised to update their installations as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share