May 29, 2023, 9:15 p.m. |

National Vulnerability Database web.nvd.nist.gov

Tuleap is an open source tool for end to end traceability of application and system developments. Tuleap Community Edition prior to version 14.8.99.60 and Tuleap Enterprise edition prior to 14.8-3 and 14.7-7, the logs of the triggered Jenkins job URLs are not properly escaped. A malicious Git administrator can setup a malicious Jenkins hook to make a victim, also a Git administrator, execute uncontrolled code. Tuleap Community Edition 14.8.99.60, Tuleap Enterprise Edition 14.8-3, and Tuleap Enterprise Edition 14.7-7 contain a …

application community cve end enterprise git jenkins job logs malicious open source system tool traceability urls version victim

SAP Security Administrator

@ FARO Technologies | Americas-US-Lake Mary-125 Bldg

Cloud Security Engineer, Specialist

@ Vanguard | Malvern, PA

Cybersecurity Assessment and Authorization Specialist

@ Booz Allen Hamilton | USA, MD, Bethesda (9000 Rockville Pike)

Network Security Specialist

@ IAG GBS | Madrid, Spain

Information System Security Officer

@ CSEngineering | Nellis Air Force Base, NV, USA

Senior Consultant, Risk and Governance

@ CIBC | Toronto-CC East 11th Floor