Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions prior to 13.9.99.95 Tuleap does not sanitize properly user inputs when constructing the SQL query to retrieve data for the tracker reports. An attacker with the capability to create a new tracker can execute arbitrary SQL queries. Users are advised to upgrade. There is no known workaround for this issue.
Metrics
Affected Vendors & Products
References
History
Wed, 23 Apr 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2022-06-29T17:55:24.000Z
Updated: 2025-04-23T18:05:22.399Z
Reserved: 2022-05-18T00:00:00.000Z
Link: CVE-2022-31058

Updated: 2024-08-03T07:03:40.226Z

Status : Modified
Published: 2022-06-29T18:15:08.807
Modified: 2024-11-21T07:03:48.397
Link: CVE-2022-31058

No data.