{"id":"CVE-2021-41148","details":"Tuleap Open ALM is a libre and open source tool for end to end traceability of application and system developments. Prior to version 11.16.99.173 of Community Edition and versions 11.16-6 and 11.15-8 of Enterprise Edition, an attacker with the ability to add one the CI widget to its personal dashboard could execute arbitrary SQL queries. Tuleap Community Edition 11.16.99.173, Tuleap Enterprise Edition 11.16-6, and Tuleap Enterprise Edition 11.15-8 contain a patch for this issue.","modified":"2026-04-09T08:15:17.308567Z","published":"2021-10-15T14:15:08.307Z","related":["GHSA-3c4q-8c35-cp63"],"references":[{"type":"ADVISORY","url":"https://tuleap.net/plugins/tracker/?aid=15028"},{"type":"FIX","url":"https://github.com/Enalean/tuleap/commit/91535add59f4b3a04b6b8eab123c002cd5af180d"},{"type":"FIX","url":"https://github.com/Enalean/tuleap/security/advisories/GHSA-3c4q-8c35-cp63"},{"type":"FIX","url":"https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=91535add59f4b3a04b6b8eab123c002cd5af180d"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/enalean/tuleap","events":[{"introduced":"0"},{"fixed":"91535add59f4b3a04b6b8eab123c002cd5af180d"}]},{"type":"GIT","repo":"https://github.com/enalean/tuleap","events":[{"introduced":"0"},{"fixed":"91535add59f4b3a04b6b8eab123c002cd5af180d"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-41148.json","unresolved_ranges":[{"events":[{"introduced":"0"},{"fixed":"11.16.99.173"}]},{"events":[{"introduced":"11.15-1"},{"fixed":"11.15-8"}]},{"events":[{"introduced":"11.16-1"},{"fixed":"11.16-6"}]}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}