Tuleap does not sanitize properly the search filter built from the
ldap_id attribute of a user during the daily synchronization when checking it the user still exist. This issue is related to request #24149, the initial fix was incomplete.
A malicious user could force accounts to be suspended or take over another account by forcing the update of the
ldap_uid attribute. Note that the malicious user either need to have site administrator capability on the Tuleap instance or be an LDAP operator with the capability to create/modify account.
CVSSv3.1 score: 6.7 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L)
OWASP LDAP Injection