CVE-2025-64482: Tuleap missing CSRF protections in the File Release System

Published Nov 12, 2025
·
Updated

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap Community Edition prior to version 16.13.99.1762267347 and Tuleap Enterprise Edition prior to versions 17.01-, 16.13-6, and 16.12-9 don't have cross-site request forgery protections in the file release system. An attacker could use this vulnerability to trick victims into changing the commit rules or immutable tags of a SVN repo. Tuleap Community Edition 16.13.99.1762267347, Tuleap Enterprise Edition 17.0-1, Tuleap Enterprise Edition 16.13-6, and Tuleap Enterprise Edition 16.12-9 fix the issue.

Affected Software

2 affected components
Tuleap Community Edition<16.13.99.1762267347
Tuleap Enterprise Edition<17.01, <16.13-6, <16.12-9

Event History

Nov 12, 2025
CVE Published
via MITRE·09:37 PM
Data Sourced
via MITRE·09:37 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2025-64482?

CVE-2025-64482 has a high severity rating due to the lack of cross-site request forgery protection.

2

How do I fix CVE-2025-64482?

You can mitigate CVE-2025-64482 by upgrading to Tuleap Community Edition version 16.13.99.1762267347 or Tuleap Enterprise Edition versions 17.01-, 16.13-6, or 16.12-9.

3

What versions are affected by CVE-2025-64482?

CVE-2025-64482 affects Tuleap Community Edition prior to version 16.13.99.1762267347 and Tuleap Enterprise Edition prior to versions 17.01-, 16.13-6, and 16.12-9.

4

Is CVE-2025-64482 a web application vulnerability?

Yes, CVE-2025-64482 is a web application vulnerability related to cross-site request forgery.

5

What should I do if I cannot upgrade due to CVE-2025-64482?

If you cannot upgrade, consider implementing additional security measures or monitoring to mitigate the risks associated with CVE-2025-64482.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203