CVE-2021-41276

Published: Dic 15, 2021 Last Modified: Nov 21, 2024 EU-VD ID: EUVD-2021-28309 Aliases: GSD-2021-41276
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 6,7
Attack Vector: network
Attack Complexity: low
Privileges Required: high
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: low
MEDIUM 6,0
Access Vector: network
Access Complexity: medium
Authentication: single
Confidentiality: partial
Integrity: partial
Availability: partial

Description

AI Translation Available

Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. In affected versions Tuleap does not sanitize properly the search filter built from the ldap_id attribute of a user during the daily synchronization. A malicious user could force accounts to be suspended or take over another account by forcing the update of the ldap_uid attribute. Note that the malicious user either need to have site administrator capability on the Tuleap instance or be an LDAP operator with the capability to create/modify account. The Tuleap instance needs to have the LDAP plugin activated and enabled for this issue to be exploitable. This issue has been patched in Tuleap Community Edition 13.2.99.31, Tuleap Enterprise Edition 13.1-5, and Tuleap Enterprise Edition 13.2-3.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0074
Percentile
0,7th
Updated

EPSS Score Trend (Last 90 Days)

74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Incomplete
Common Consequences
Security Scopes Affected:
Confidentiality Access Control Other Integrity Non-Repudiation
Potential Impacts:
Read Application Data Bypass Protection Mechanism Alter Execution Logic Other Hide Activities
Applicable Platforms
All platforms may be affected
View CWE Details
90

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')

Draft
Common Consequences
Security Scopes Affected:
Confidentiality Integrity Availability
Potential Impacts:
Execute Unauthorized Code Or Commands Read Application Data Modify Application Data
Applicable Platforms
Technologies: Database Server
View CWE Details
Application

Tuleap by Enalean

Version Range Affected
From 13.1-1 (inclusive)
To 13.1-5 (exclusive)
cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Tuleap by Enalean

Version Range Affected
To 13.2.99.31 (exclusive)
cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Tuleap by Enalean

Version Range Affected
From 13.2-1 (inclusive)
To 13.2-3 (exclusive)
cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://github.com/Enalean/tuleap/commit/bd47f29847fcd6a68d359bc8aefb8749bb8a1b…
https://github.com/Enalean/tuleap/security/advisories/GHSA-887w-pv2r-x8pm
https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=bd47f29847fcd6a6…
https://tuleap.net/plugins/tracker/?aid=24149
Issue Tracking Patch Vendor Advisory
https://tuleap.net/plugins/tracker/?aid=24149
https://github.com/Enalean/tuleap/commit/bd47f29847fcd6a68d359bc8aefb8749bb8a1b…
https://github.com/Enalean/tuleap/security/advisories/GHSA-887w-pv2r-x8pm
https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=bd47f29847fcd6a6…
https://tuleap.net/plugins/tracker/?aid=24149
Issue Tracking Patch Vendor Advisory
https://tuleap.net/plugins/tracker/?aid=24149