CVE 4.6 MEDIUM

Tuleap is missing CSRF protection in the Overview inconsistent items_CVE-2026-24007

4.6 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L

Description

Tuleap is an Open Source Suite for management of software development and collaboration. Tuleap is missing CSRF protection in the Overview inconsistent items. An attacker could use this vulnerability to trick victims into repairing inconsistent items (creating artifact links from the release). This vulnerability is fixed in Tuleap Community Edition 17.0.99.1768924735 and Tuleap Enterprise Edition 17.2-5, 17.1-6, and 17.0-9.

Basic Information

ID CVE-2026-24007
Source GitHub_M
Published Feb 2, 2026 at 19:52

Affected Product

Vendor Enalean
Product tuleap
Version < 17.0.99.1768924735
Affected Versions Enalean tuleap < 17.0.99.1768924735

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.