关键漏洞信息 漏洞标题 Missing CSRF protection on tracker reports manipulation 严重性 等级: Moderate (4.6/10) 影响 描述: An attacker could use this vulnerability to trick victims into changing the canned responses. 受影响版本 Tuleap Community Edition: < 16.8.99.1749830289 Tuleap Enterprise Edition: < 16.9-1 修复版本 Tuleap Community Edition: 16.8.99.1749830289 Tuleap Enterprise Edition: 16.9-1 CVE ID CVE-2025-50179 弱点 CWE-352 CVSS v3 基本指标 攻击向量: Network 攻击复杂度: Low 所需权限: Low 用户交互: Required 范围: Unchanged 机密性影响: None 完整性影响: Low 可用性影响: Low 参考链接 request #43357 Missing CSRF protection on tracker reports manipulation commit 0f9aab6 tuleap/stable commit