CVE-2025-30155: Tuleap does not enforce read permissions on parent trackers in the REST API
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap does not enforce read permissions on parent trackers in the REST API. This vulnerability is fixed in Tuleap Community Edition 16.5.99.1742392651 and Tuleap Enterprise Edition 16.5-5 and 16.4-8.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30155?
CVE-2025-30155 is considered a high severity vulnerability due to improper enforcement of read permissions.
How do I fix CVE-2025-30155?
To fix CVE-2025-30155, upgrade to Tuleap Community Edition 16.5.99.1742392651 or Tuleap Enterprise Edition 16.5-5 or newer.
What type of vulnerability is CVE-2025-30155?
CVE-2025-30155 is an access control vulnerability affecting the REST API of Tuleap.
Which versions of Tuleap are affected by CVE-2025-30155?
CVE-2025-30155 affects Tuleap Community Edition up to version 16.5.99.1742392651 and Tuleap Enterprise Edition versions between 16.4-8 and 16.5-5.
Is CVE-2025-30155 a remote exploitation vulnerability?
Yes, CVE-2025-30155 can be exploited remotely through the REST API due to improper permission checks.