CVE-2025-52899

T

uleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition prior to version 16.9.99.1750843170 and Tuleap Enterprise Edition prior to 16.8-4 and 16.9-2, the forgot password form allows for user enumeration. This is fixed in Tuleap Community Edition version 16.9.99.1750843170 and Tuleap Enterprise Edition 16.8-4 and 16.9-2.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*

History

22 Aug 2025, 15:34

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-29 20:15

Updated : 2025-08-22 15:34


NVD link : CVE-2025-52899

Mitre link : CVE-2025-52899

CVE.ORG link : CVE-2025-52899


JSON object : View

Products Affected
CWE
CWE-204

Observable Response Discrepancy