•  
      request #45583 FRS project administrator can access releases in all projects
    Infos
    #45583
    Thomas Gerbet (tgerbet)
    2025-12-08 10:33
    2025-11-05 10:51
    47306
    Details
    FRS project administrator can access releases in all projects

    A FRS/project administrators in one projects can access information of file release system services in all projects without having the rights to access them.

    Impact

    Attackers can use this to access file release system information in project they do not have access to.
    CVSSv3.1 score: 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)

    Exploitation

    1. Be a project/FRS admin in a project A
    2. Have a project B with the FRS service enabled and some content you should not have access to
    3. Go to https://tuleap.example.com/file/<project_id_A>/package/<package_id_project_B>

    References

    CWE 639
    CVE-2025-64497

    Delivery/File release system
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Thomas Gerbet (tgerbet)
    Closed
    2025-11-06
    Attachments
    Empty
    References

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2025-11-12 09:56
    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes
    User avatar
    Thomas Gerbet (tgerbet)2025-11-07 09:03
    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes