Tuleap does not sanitize properly the search filter built from the ldap_id
attribute of a user during the daily synchronization when checking it the user still exist. This issue is related to request #24149, the initial fix was incomplete.
Impact
A malicious user could force accounts to be suspended or take over another account by forcing the update of the ldap_uid
attribute. Note that the malicious user either need to have site administrator capability on the Tuleap instance or be an LDAP operator with the capability to create/modify account.
CVSSv3.1 score: 6.7 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L)
References
CWE 90
OWASP LDAP Injection
CVE-2021-43782