The password to connect the Redis instance is not purged from the archive generated with tuleap collect-system-data.
Impact
Password to connect Redis instance is leaked in debug archives that is likely to be used by support teams that should not have access to it.
CVSSv3.1 score: 5.3 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N)
References
CWE 538
CVE-2025-27150