PT-2023-23583 · Git+2 · Git+3

Tgerbet

+1

·

Published

2023-05-29

·

Updated

2023-06-05

·

CVE-2023-32072

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Tuleap Community Edition versions prior to 14.8.99.60 Tuleap Enterprise Edition versions prior to 14.8-3 Tuleap Enterprise Edition versions prior to 14.7-7
Description The issue concerns the improper escaping of logs of triggered Jenkins job URLs. A malicious Git administrator can set up a malicious Jenkins hook, potentially making a victim, also a Git administrator, execute uncontrolled code.
Recommendations For Tuleap Community Edition versions prior to 14.8.99.60, update to version 14.8.99.60 or later. For Tuleap Enterprise Edition versions prior to 14.8-3, update to version 14.8-3 or later. For Tuleap Enterprise Edition versions prior to 14.7-7, update to version 14.7-7 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-32072
GHSA-6PRC-J58R-FMJQ

Affected Products

Git
Jenkins
Tuleap Community Edition
Tuleap Enterprise Edition