SQL injection in CVS revisions browser
CVE-2021-41155

8.8HIGH

Key Information:

Vendor

Enalean

Status
Vendor
CVE Published:
18 October 2021

What is CVE-2021-41155?

Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versions Tuleap does not sanitize properly user inputs when constructing the SQL query to browse and search revisions in the CVS repositories. The following versions contain the fix: Tuleap Community Edition 11.17.99.146, Tuleap Enterprise Edition 11.17-5, Tuleap Enterprise Edition 11.16-7.

Affected Version(s)

tuleap < 11.17.99.146 < 11.17.99.146

tuleap >= 11.17-1, < 11.17-5 < 11.17-1, 11.17-5

tuleap >= 11.16-1, < 11.16-7 < 11.16-1, 11.16-7

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.