CVE-2025-29929: Tuleap is missing CSRF protection on tracker hierarchy administration
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap is missing CSRF protection on tracker hierarchy administration. An attacker could use this vulnerability to trick victims into submitting or editing artifacts or follow-up comments. This vulnerability is fixed in Tuleap Community Edition 16.5.99.1742306712 and Tuleap Enterprise Edition 16.5-5 and 16.4-8.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-29929?
CVE-2025-29929 is rated as a medium severity vulnerability due to the lack of CSRF protection on tracker hierarchy administration.
How do I fix CVE-2025-29929?
To fix CVE-2025-29929, upgrade to a version of Tuleap that contains the security patches for this vulnerability.
Which versions of Tuleap are affected by CVE-2025-29929?
CVE-2025-29929 affects Tuleap Community Edition versions up to 16.5.99.1742306712 and Tuleap Enterprise Edition versions from 16.4 to 16.5-5.
What type of attacks can CVE-2025-29929 enable?
CVE-2025-29929 can potentially enable attackers to trick users into submitting or editing artifacts or comments without their consent.
Is there a workaround for CVE-2025-29929?
Currently, the best method to mitigate CVE-2025-29929 is to apply the relevant updates or patches provided by Tuleap.