CVE-2021-41276
Last modified
CVE-2021-41276 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. In affected versions Tuleap does not sanitize properly the search filter built from the ldap_id attribute of a user during the daily synchronization. EPSS estimates a 1.48% chance of exploitation in the next 30 days.
Description
Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. In affected versions Tuleap does not sanitize properly the search filter built from the ldap_id attribute of a user during the daily synchronization. A malicious user could force accounts to be suspended or take over another account by forcing the update of the ldap_uid attribute. Note that the malicious user either need to have site administrator capability on the Tuleap instance or be an LDAP operator with the capability to create/modify account. The Tuleap instance needs to have the LDAP plugin activated and enabled for this issue to be exploitable. This issue has been patched in Tuleap Community Edition 13.2.99.31, Tuleap Enterprise Edition 13.1-5, and Tuleap Enterprise Edition 13.2-3.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Enalean | Tuleap | < 13.2.99.31 |
| Enalean | Tuleap | >= 13.1-1, < 13.1-5 |
| Enalean | Tuleap | >= 13.2-1, < 13.2-3 |
References
- https://github.com/Enalean/tuleap/commit/bd47f29847fcd6a68d359bc8aefb8749bb8a1b7cPatch, Third Party Advisory
- https://github.com/Enalean/tuleap/security/advisories/GHSA-887w-pv2r-x8pmThird Party Advisory
- https://tuleap.net/plugins/tracker/?aid=24149Issue Tracking, Patch, Vendor Advisory
- https://github.com/Enalean/tuleap/commit/bd47f29847fcd6a68d359bc8aefb8749bb8a1b7cPatch, Third Party Advisory
- https://github.com/Enalean/tuleap/security/advisories/GHSA-887w-pv2r-x8pmThird Party Advisory
- https://tuleap.net/plugins/tracker/?aid=24149Issue Tracking, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-41276?
How severe is CVE-2021-41276?
How do I fix CVE-2021-41276?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-41270Symfony/Serializer handles serializing and deserializing dat…6.5
- CVE-2021-41271Discourse is a platform for community discussion. In affecte…5.3
- CVE-2021-41272Besu is an Ethereum client written in Java. Starting in vers…7.5
- CVE-2021-41273Pterodactyl is an open-source game server management panel b…4.3
- CVE-2021-41274solidus_auth_devise provides authentication services for the…8.8
- CVE-2021-41275spree_auth_devise is an open source library which provides a…8.8
- CVE-2021-41277Metabase is an open source data analytics platform. In affec…7.5
- CVE-2021-41278Functions SDK for EdgeX is meant to provide all the plumbing…5.7
- CVE-2021-41279BaserCMS is an open source content management system with a …8.8
- CVE-2021-4128When transitioning in and out of fullscreen mode, a graphics…6.5
- CVE-2021-41280Sharetribe Go is a source available marketplace software. In…9.8
- CVE-2021-41281Synapse is a package for Matrix homeservers written in Pytho…7.5
Are you affected by CVE-2021-41276?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
