PT-2021-23127 · Unknown · Tuleap Community Edition+1

Tgerbet

+1

·

Published

2021-10-15

·

Updated

2021-10-21

·

CVE-2021-41147

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tuleap Community Edition versions prior to 11.16.99.173 Tuleap Enterprise Edition versions prior to 11.16-6 and 11.15-8
Description The issue allows an attacker with admin rights in one agile dashboard service to execute arbitrary SQL queries.
Recommendations For Tuleap Community Edition versions prior to 11.16.99.173, update to version 11.16.99.173 or later. For Tuleap Enterprise Edition versions prior to 11.16-6, update to version 11.16-6 or later. For Tuleap Enterprise Edition version 11.15-8, update to a later version that contains the patch for this issue.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41147
GHSA-J2MQ-65WV-PRMP

Affected Products

Tuleap Community Edition
Tuleap Enterprise Edition