High severity8.8NVD Advisory· Published Oct 18, 2021· Updated Jun 17, 2026
CVE-2021-41154
CVE-2021-41154
Description
Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versions an attacker with read access to a "SVN core" repository could execute arbitrary SQL queries. The following versions contain the fix: Tuleap Community Edition 11.17.99.144, Tuleap Enterprise Edition 11.17-5, Tuleap Enterprise Edition 11.16-7.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:*+ 3 more
- cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:*range: <11.17.99.144
- cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*range: >=11.16-1,<11.16-7
- (no CPE)range: before 11.17.99.144, 11.17-11.17.99.143, 11.16-11.16.99.7
- (no CPE)range: < 11.17.99.144
Patches
Vulnerability mechanics
References
4- github.com/Enalean/tuleap/commit/ab12b686ced4cf233d3b15b08da008e0553eb6a6nvdPatchThird Party Advisory
- tuleap.net/plugins/git/tuleap/tuleap/stablenvdPatchVendor Advisory
- github.com/Enalean/tuleap/security/advisories/GHSA-6462-gfv9-jf83nvdThird Party Advisory
- tuleap.net/plugins/tracker/nvdVendor Advisory
News mentions
0No linked articles in our index yet.