CVE-2022-31058: SQL injection via the field name of a tracker in Tuleap
Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions prior to 13.9.99.95 Tuleap does not sanitize properly user inputs when constructing the SQL query to retrieve data for the tracker reports. An attacker with the capability to create a new tracker can execute arbitrary SQL queries. Users are advised to upgrade. There is no known workaround for this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-31058?
CVE-2022-31058 is a vulnerability in Tuleap that allows an attacker to execute arbitrary SQL queries.
What is the severity of CVE-2022-31058?
CVE-2022-31058 has a severity rating of 7.2 (high).
How does CVE-2022-31058 impact Tuleap?
CVE-2022-31058 allows an attacker to manipulate SQL queries and retrieve sensitive data from Tuleap.
Is there a fix available for CVE-2022-31058?
Yes, a fix is available for CVE-2022-31058. Users should update to version 13.9.99.95 or later of Tuleap.
Where can I find more information about CVE-2022-31058?
You can find more information about CVE-2022-31058 in the official Tuleap security advisory and the GitHub commit.