HIGH🇵🇱 Wersja polska

CVE-2021-41154

CVSS 8.8v3.1pub. 2021-10-18upd. 2024-11-21

Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versions an attacker with read access to a "SVN core" repository could execute arbitrary SQL queries. The following versions contain the fix: Tuleap Community Edition 11.17.99.144, Tuleap Enterprise Edition 11.17-5, Tuleap Enterprise Edition 11.16-7.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Enalean Tuleap

    APP
    Enalean
    < 11.17.99.14411.16-1 – 11.16-7 (excl.)11.17-1 – 11.17-5 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2018-17298CRITICAL9.8PL ✓same product

Enalean Tuleap: linki reset hasła nie są unieważniane po zmianie hasła

CVE-2018-7538CRITICAL9.8PL ✓same product

SQL Injection w module tracker platformy Enalean Tuleap

CVE-2024-30246HIGH7.6same product

Tuleap is an Open Source Suite to improve management of software developments and collaboration. A malicious u...

CVE-2022-31058HIGH7.2same product

Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In vers...

CVE-2021-43806HIGH8.8same product

Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. In ...