CVE-2025-27150
CVE-2025-27150
Título es
CVE-2025-27150
Mar, 04/03/2025 – 17:15
Tipo
CWE-538
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2025-27150
Descripción en
Tuleap is an Open Source Suite to improve management of software developments and collaboration. The password to connect the Redis instance is not purged from the archive generated with tuleap collect-system-data. These archives are likely to be used by support teams that should not have access to this password. The vulnerability is fixed in Tuleap Community Edition 16.4.99.1740492866 and Tuleap Enterprise Edition 16.4-6 and 16.3-11.
04/03/2025
04/03/2025
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Gravedad 3.1 (CVSS 3.1 Base Score)
5.30
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
MEDIUM
Referencias
https://github.com/Enalean/tuleap/commit/a6702622a8db969a17522b8fac0774afdb1c916f
https://github.com/Enalean/tuleap/security/advisories/GHSA-jc5r-684x-j46q
https://tuleap.net/plugins/tracker/?aid=41870
Enviar en el boletín
Off