CVE-2025-64760: Tuleap has missing CSRF protections in its tracker trigger management system
Tuleap is a free and open source suite for management of software development and collaboration. Versions of Tuleap Community Edition prior to 17.0.99.1763126988 and Tuleap Enterprise Edition prior to 17.0-3 and 16.13-8 have missing CSRF protections which allow attackers to create or remove tracker triggers. This issue is fixed in Tuleap Community Edition version 17.0.99.1763126988 and Tuleap Enterprise Edition versions 17.0-3 and 16.13-8.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64760?
CVE-2025-64760 is considered to have a high severity due to the lack of CSRF protections allowing potential unauthorized actions.
What versions are affected by CVE-2025-64760?
CVE-2025-64760 affects Tuleap Community Edition prior to version 17.0.99.1763126988 and Tuleap Enterprise Edition prior to versions 17.0-3 and 16.13-8.
How do I fix CVE-2025-64760?
To fix CVE-2025-64760, upgrade to Tuleap Community Edition version 17.0.99.1763126988 or Tuleap Enterprise Edition versions 17.0-3 or 16.13-8 or later.
What type of vulnerability is identified by CVE-2025-64760?
CVE-2025-64760 is a Cross-Site Request Forgery (CSRF) vulnerability.
What can attackers do due to CVE-2025-64760?
Attackers can exploit CVE-2025-64760 to execute unauthorized actions on behalf of legitimate users without their consent.