CVE-2025-27094
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2025-27094 affects Tuleap, an open-source software development management tool. A malicious user with access to a tracker can force-reset certain field configurations, resulting in potential information loss. Specifically, the date field's display time attribute, multiselectbox field's size attribute, text field's default value, number of rows, and columns attributes, and string field's default value, size, and max characters attributes are all lost when added as criteria in a saved report. In certain Tuleap Community Edition versions (16.4.99.1739806825 to 16.4.99.1739877910), this vulnerability can also be exploited to deny access to tracker data. This issue has been addressed in Tuleap Community Edition 16.4-4 and Tuleap Enterprise Edition 16.3-9 and 16.4-4.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.