SQL injection in CVS revisions browser
CVE-2021-41155
8.8HIGH
What is CVE-2021-41155?
Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versions Tuleap does not sanitize properly user inputs when constructing the SQL query to browse and search revisions in the CVS repositories. The following versions contain the fix: Tuleap Community Edition 11.17.99.146, Tuleap Enterprise Edition 11.17-5, Tuleap Enterprise Edition 11.16-7.
Affected Version(s)
tuleap < 11.17.99.146 < 11.17.99.146
tuleap >= 11.17-1, < 11.17-5 < 11.17-1, 11.17-5
tuleap >= 11.16-1, < 11.16-7 < 11.16-1, 11.16-7
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
