Onedev Project
Onedev Project Onedev: vulnerabilidades y CVE
Onedev Project Onedev tiene 18 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE18
Últimos 12 meses0
Críticas6
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-45309 | Alta (8.7) | 25% | — | 21 oct 2024 | OneDev is a Git server with CI/CD, kanban, and packages. A vulnerability in versions prior to 11.0.9 allows unauthenticated users to read arbitrary files accessible by the OneDev server process. This issue has been… |
| CVE-2023-24828 | Alta (8.8) | 0.71% | — | 8 feb 2023 | Onedev is a self-hosted Git Server with CI/CD and Kanban. In versions prior to 7.9.12 the algorithm used to generate access token and password reset keys was not cryptographically secure. Existing normal users (or… |
| CVE-2022-38301 | Alta (8.8) | 1.4% | — | 14 sept 2022 | Onedev v7.4.14 contains a path traversal vulnerability which allows attackers to access restricted files and directories via uploading a crafted JAR file into the directory /opt/onedev/lib. |
| CVE-2022-39208 | Alta (7.5) | 1.9% | — | 13 sept 2022 | Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. All files in the /opt/onedev/sites/ directory are exposed and can be read by unauthenticated users. This directory contains all projects, including… |
| CVE-2022-39207 | Media (5.4) | 1.0% | — | 13 sept 2022 | Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. During CI/CD builds, it is possible to save build artifacts for later retrieval. They can be accessed through OneDev's web UI after the successful… |
| CVE-2022-39206 | Crítica (9.9) | 2.1% | — | 13 sept 2022 | Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. When using Docker-based job executors, the Docker socket (e.g. /var/run/docker.sock on Linux) is mounted into each Docker step. Users that can… |
| CVE-2022-39205 | Crítica (9.8) | 2.4% | — | 13 sept 2022 | Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. In versions of Onedev prior to 7.3.0 unauthenticated users can take over a OneDev instance if there is no properly configured reverse proxy. The… |
| CVE-2021-32651 | Media (4.3) | 1.1% | — | 1 jun 2021 | OneDev is a development operations platform. If the LDAP external authentication mechanism is enabled in OneDev versions 4.4.1 and prior, an attacker can manipulate a user search filter to send forged queries to the… |
| CVE-2021-21251 | Alta (8.8) | 13% | — | 15 ene 2021 | OneDev is an all-in-one devops platform. In OneDev before version 4.0.3 there is a critical "zip slip" vulnerability. This issue may lead to arbitrary file write. The KubernetesResource REST endpoint untars user… |
| CVE-2021-21250 | Media (6.5) | 0.93% | — | 15 ene 2021 | OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which may lead to arbitrary file read. When BuildSpec is provided in XML format, the spec is processed by… |
| CVE-2021-21249 | Alta (8.8) | 2.9% | — | 15 ene 2021 | OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is an issue involving YAML parsing which can lead to post-auth remote code execution. In order to parse and process YAML files, OneDev uses… |
| CVE-2021-21248 | Alta (8.8) | 1.5% | — | 15 ene 2021 | OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability involving the build endpoint parameters. InputSpec is used to define parameters of a Build spec. It does so by… |
| CVE-2021-21247 | Alta (8.8) | 1.5% | — | 15 ene 2021 | OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the application's BasePage registers an AJAX event listener (`AbstractPostAjaxBehavior`) in all pages other than the login page. This listener… |
| CVE-2021-21246 | Alta (7.5) | 49% | — | 15 ene 2021 | OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the REST UserResource endpoint performs a security check to make sure that only administrators can list user details. However for the… |
| CVE-2021-21245 | Crítica (9.8) | 1.2% | — | 15 ene 2021 | OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, AttachmentUploadServlet also saves user controlled data (`request.getInputStream()`) to a user specified location… |
| CVE-2021-21242 | Crítica (9.8) | 74% | — | 15 ene 2021 | OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which can lead to pre-auth remote code execution. AttachmentUploadServlet deserializes untrusted data from the… |
| CVE-2021-21244 | Crítica (9.8) | 1.5% | — | 15 ene 2021 | OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, There is a vulnerability that enabled pre-auth server side template injection via Bean validation message tampering. Full details in the reference… |
| CVE-2021-21243 | Crítica (9.8) | 54% | — | 15 ene 2021 | OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, a Kubernetes REST endpoint exposes two methods that deserialize untrusted data from the request body. These endpoints do not enforce any… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.