Impact
This vulnerability is an OS Command Injection flaw (CWE‑78) that allows an attacker to execute arbitrary operating system commands on the server where Tuleap Enterprise Edition is installed. The flaw arises through an unspecified input channel, meaning the impact includes potential full system compromise and unauthorized access to data or services hosted on the same machine.
Affected Systems
The affected product is Dassault Systèmes Tuleap Enterprise Edition, specifically releases 17.3, 17.4, and 17.5. No other versions or editions are listed as impacted in the advisory.
Risk and Exploitability
With a CVSS score of 8.8, this issue is classified as high severity. The EPSS score is 2%, indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves an input that is executed by the system, probably via the web interface or custom integrations, but the exact method is not detailed in the advisory. Consequently, the risk remains significant due to the potential for remote exploitation and full control of the host.
OpenCVE Enrichment