Enalean Tuleap是法国Enalean公司的一个自由的开源工具。用于应用程序和系统开发的端到端可追溯性。 Enalean Tuleap存在安全漏洞,该漏洞源于FRS REST端点中的未授权访问发布说明内容或信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-30203 | 4.8 MEDIUM | Tuleap allows XSS via the content of RSS feeds in the RSS widgets |
| CVE-2025-29929 | 4.6 MEDIUM | Tuleap is missing CSRF protection on tracker hierarchy administration |
| CVE-2025-29766 | 4.6 MEDIUM | Tuleap has missing CSRF protections on artifact submission & edition from the tracker view |
| CVE-2025-30155 | 4.3 MEDIUM | Tuleap does not enforce read permissions on parent trackers in the REST API |
No comments yet