PT-2021-23128 · Unknown · Tuleap Community Edition+1

Tgerbet

+1

·

Published

2021-10-15

·

Updated

2021-10-21

·

CVE-2021-41148

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tuleap Community Edition versions prior to 11.16.99.173 Tuleap Enterprise Edition versions prior to 11.16-6 Tuleap Enterprise Edition version 11.15-8 and earlier
Description The issue allows an attacker with the ability to add the CI widget to their personal dashboard to execute arbitrary SQL queries.
Recommendations For Tuleap Community Edition versions prior to 11.16.99.173, update to version 11.16.99.173 or later. For Tuleap Enterprise Edition versions prior to 11.16-6, update to version 11.16-6 or later. For Tuleap Enterprise Edition version 11.15-8 and earlier, update to version 11.15-8 or later, or apply the patch from Tuleap Enterprise Edition 11.16-6.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41148
GHSA-3C4Q-8C35-CP63

Affected Products

Tuleap Community Edition
Tuleap Enterprise Edition