CVE-2025-27156
CVE-2025-27156
Título es
CVE-2025-27156
Mar, 04/03/2025 – 17:15
Tipo
CWE-79
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2025-27156
Descripción en
Tuleap is an Open Source Suite to improve management of software developments and collaboration. The mass emailing features do not sanitize the content of the HTML emails. A malicious user could use this issue to facilitate a phishing attempt or to indirectly exploit issues in the recipients mail clients. This vulnerability is fixed in Tuleap Community Edition 16.4.99.1740567344 and Tuleap Enterprise Edition 16.4-6 and 16.3-11.
04/03/2025
04/03/2025
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N
Gravedad 3.1 (CVSS 3.1 Base Score)
4.10
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
MEDIUM
Referencias
https://github.com/Enalean/tuleap/commit/a0bc657297b405debce1f5bcbbb30c733f3f09bd
https://github.com/Enalean/tuleap/security/advisories/GHSA-x2v2-xr59-c9cf
https://tuleap.net/plugins/tracker/?aid=42177
Enviar en el boletín
Off