CVE-2021-41154

Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versions an attacker with read access to a "SVN core" repository could execute arbitrary SQL queries. The following versions contain the fix: Tuleap Community Edition 11.17.99.144, Tuleap Enterprise Edition 11.17-5, Tuleap Enterprise Edition 11.16-7.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*

History

No history.

Information

Published : 2021-10-18 22:15

Updated : 2024-02-28 18:48


NVD link : CVE-2021-41154

Mitre link : CVE-2021-41154

CVE.ORG link : CVE-2021-41154


JSON object : View

Products Affected

enalean

  • tuleap
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')