VYPR
Medium severity5.4NVD Advisory· Published Oct 14, 2021· Updated Jun 17, 2026

CVE-2021-41142

CVE-2021-41142

Description

Tuleap Open ALM is a libre and open source tool for end to end traceability of application and system developments. There is a cross-site scripting vulnerability in Tuleap Community Edition prior to 12.11.99.25 and Tuleap Enterprise Edition 12.11-2. A malicious user with the capability to add and remove attachment to an artifact could force a victim to execute uncontrolled code. Tuleap Community Edition 11.17.99.146 and Tuleap Enterprise Edition 12.11-2 contain a fix for the issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • Enalean/Tuleap4 versions
    cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:*+ 3 more
    • cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:*range: <11.17.99.146
    • cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*range: <12.11-2
    • (no CPE)
    • (no CPE)range: < 12.11.99.25
  • Range: <12.11.99.25, <12.11-2

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.