CVE-2021-43806
Last modified
CVE-2021-43806 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. In affected versions Tuleap does not sanitize properly user settings when constructing the SQL query to browse and search commits in the CVS repositories. EPSS estimates a 1.54% chance of exploitation in the next 30 days.
Description
Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. In affected versions Tuleap does not sanitize properly user settings when constructing the SQL query to browse and search commits in the CVS repositories. A authenticated malicious user with read access to a CVS repository could execute arbitrary SQL queries. Tuleap instances without an active CVS repositories are not impacted. The following versions contain the fix: Tuleap Community Edition 13.2.99.155, Tuleap Enterprise Edition 13.1-7, and Tuleap Enterprise Edition 13.2-6.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Enalean | Tuleap | < 13.2.99.155 |
| Enalean | Tuleap | >= 13.1-1, < 13.1-7 |
| Enalean | Tuleap | >= 13.2-1, < 13.2-6 |
References
- https://github.com/Enalean/tuleap/commit/b82be896b00a787ed46a77bd4700e8fccfe2e5baPatch, Third Party Advisory
- https://github.com/Enalean/tuleap/security/advisories/GHSA-x8fr-8gvw-cc4vPatch, Third Party Advisory
- https://tuleap.net/plugins/tracker/?aid=24202Issue Tracking, Patch, Vendor Advisory
- https://github.com/Enalean/tuleap/commit/b82be896b00a787ed46a77bd4700e8fccfe2e5baPatch, Third Party Advisory
- https://github.com/Enalean/tuleap/security/advisories/GHSA-x8fr-8gvw-cc4vPatch, Third Party Advisory
- https://tuleap.net/plugins/tracker/?aid=24202Issue Tracking, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-43806?
How severe is CVE-2021-43806?
How do I fix CVE-2021-43806?
Are you affected by CVE-2021-43806?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
