CVE-2021-41147
7.2 HIGHTuleap Open ALM is a libre and open source tool for end to end traceability of application and system developments
Published: 2021-10-15 · Last updated: 2026-06-17
Severity and scoring
- CVSS
- 7.2 HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-89
Affected products
| Vendor | Product |
|---|---|
| enalean | tuleap |
Description
Tuleap Open ALM is a libre and open source tool for end to end traceability of application and system developments. Prior to version 11.16.99.173 of Community Edition and versions 11.16-6 and 11.15-8 of Enterprise Edition, an attacker with admin rights in one agile dashboard service can execute arbitrary SQL queries. Tuleap Community Edition 11.16.99.173, Tuleap Enterprise Edition 11.16-6, and Tuleap Enterprise Edition 11.15-8 contain a patch for this issue.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2021-41147
- [Patch]https://github.com/Enalean/tuleap/commit/d6b2f8b8c5098938bc094726a4826479ddbee941
- [Patch]https://github.com/Enalean/tuleap/security/advisories/GHSA-j2mq-65wv-prmp
- [Patch]https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=d6b2f8b8c5098938bc094726a4826479ddbee941
- [Vendor advisory]https://tuleap.net/plugins/tracker/?aid=15131
- [Patch]https://github.com/Enalean/tuleap/commit/d6b2f8b8c5098938bc094726a4826479ddbee941
- [Patch]https://github.com/Enalean/tuleap/security/advisories/GHSA-j2mq-65wv-prmp
- [Patch]https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=d6b2f8b8c5098938bc094726a4826479ddbee941
- [Vendor advisory]https://tuleap.net/plugins/tracker/?aid=15131
Related CVEs
Same vendor
- CVE-2021-41155 — Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration (8.8 HIGH)
- CVE-2021-41154 — Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration (8.8 HIGH)
- CVE-2021-41148 — Tuleap Open ALM is a libre and open source tool for end to end traceability of application and system developments (8.8 HIGH)
- CVE-2021-41142 — Tuleap Open ALM is a libre and open source tool for end to end traceability of application and system developments (5.4 MEDIUM)
Same CWE
- CVE-2026-52715 — Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions (9.3 CRITICAL)
- CVE-2026-52712 — Subscriber SQL Injection in Attendance Manager <= 0.6.2 versions (7.6 HIGH)
- CVE-2026-49772 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events C... (9.3 CRITICAL)
- CVE-2026-39581 — Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions (8.5 HIGH)
- CVE-2026-39574 — Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions (9.3 CRITICAL)