High severity7.2NVD Advisory· Published Jun 29, 2022· Updated Jun 17, 2026
CVE-2022-31058
CVE-2022-31058
Description
Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions prior to 13.9.99.95 Tuleap does not sanitize properly user inputs when constructing the SQL query to retrieve data for the tracker reports. An attacker with the capability to create a new tracker can execute arbitrary SQL queries. Users are advised to upgrade. There is no known workaround for this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4Patches
Vulnerability mechanics
References
4- github.com/Enalean/tuleap/commit/b91bcd57c8344ec2a4c1833629e400cef4dd901anvdPatchThird Party Advisory
- tuleap.net/plugins/git/tuleap/tuleap/stablenvdPatchVendor Advisory
- github.com/Enalean/tuleap/security/advisories/GHSA-4v2p-rwq9-3vjfnvdThird Party Advisory
- tuleap.net/plugins/tracker/nvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.