CVE-2021-43806
SQL injection in Tuleap
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. In affected versions Tuleap does not sanitize properly user settings when constructing the SQL query to browse and search commits in the CVS repositories. A authenticated malicious user with read access to a CVS repository could execute arbitrary SQL queries. Tuleap instances without an active CVS repositories are not impacted. The following versions contain the fix: Tuleap Community Edition 13.2.99.155, Tuleap Enterprise Edition 13.1-7, and Tuleap Enterprise Edition 13.2-6.
Tuleap es una herramienta libre y de código abierto para la trazabilidad de extremo a extremo de los desarrollos de aplicaciones y sistemas. En las versiones afectadas, Tuleap no sanea correctamente la configuración del usuario cuando construye la consulta SQL para navegar y buscar commits en los repositorios CVS. Un usuario malicioso autenticado con acceso de lectura a un repositorio CVS podría ejecutar consultas SQL arbitrarias. Las instancias de Tuleap sin repositorios CVS activos no están afectadas. Las siguientes versiones contienen la corrección: Tuleap Community Edition versión 13.2.99.155, Tuleap Enterprise Edition versión 13.1-7, y Tuleap Enterprise Edition versión 13.2-6
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-11-16 CVE Reserved
- 2021-12-15 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (4)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Enalean Search vendor "Enalean" | Tuleap Search vendor "Enalean" for product "Tuleap" | < 13.2.99.155 Search vendor "Enalean" for product "Tuleap" and version " < 13.2.99.155" | community |
Affected
| ||||||
Enalean Search vendor "Enalean" | Tuleap Search vendor "Enalean" for product "Tuleap" | >= 13.1-1 < 13.1-7 Search vendor "Enalean" for product "Tuleap" and version " >= 13.1-1 < 13.1-7" | enterprise |
Affected
| ||||||
Enalean Search vendor "Enalean" | Tuleap Search vendor "Enalean" for product "Tuleap" | >= 13.2-1 < 13.2-6 Search vendor "Enalean" for product "Tuleap" and version " >= 13.2-1 < 13.2-6" | enterprise |
Affected
|