PT-2021-7107 · Unknown+2 · Tuleap Enterprise Edition+2
Tgerbet
+1
·
Published
2021-11-23
·
Updated
2022-08-09
·
CVE-2021-43782
CVSS v2.0
8.5
High
| Vector | AV:N/AC:M/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Tuleap versions prior to 13.2.99.83
Tuleap Enterprise Edition versions prior to 13.1-6
Tuleap Enterprise Edition versions prior to 13.2-4
Description
The issue exists due to improper sanitization of the search filter built from the
ldap id attribute of a user during daily synchronization. A malicious user could force accounts to be suspended or take over another account by forcing the update of the ldap uid attribute. This can be done by a user with site administrator capability on the Tuleap instance or an LDAP operator with the capability to create/modify accounts, provided the Tuleap instance has the LDAP plugin activated and enabled.Recommendations
For versions prior to 13.2.99.83, update to Tuleap Community Edition 13.2.99.83 or later.
For Tuleap Enterprise Edition versions prior to 13.1-6, update to Tuleap Enterprise Edition 13.1-6 or later.
For Tuleap Enterprise Edition versions prior to 13.2-4, update to Tuleap Enterprise Edition 13.2-4 or later.
As a temporary workaround, consider restricting access to the LDAP plugin or disabling it until a patch is applied. Additionally, limiting site administrator capabilities and LDAP operator privileges can help minimize the risk of exploitation.
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ldap
Tuleap
Tuleap Enterprise Edition