Onedev Project
Onedev Project Onedev: vulnerabilities and CVEs
Onedev Project Onedev has 18 published vulnerabilities, 0 of them in the last 12 months. 6 are rated critical and 0 are listed by CISA as actively exploited.
CVEs18
Last 12 months0
Critical6
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45309 | High (8.7) | 25% | — | Oct 21, 2024 | OneDev is a Git server with CI/CD, kanban, and packages. A vulnerability in versions prior to 11.0.9 allows unauthenticated users to read arbitrary files accessible by the OneDev server process. This issue has been… |
| CVE-2023-24828 | High (8.8) | 0.71% | — | Feb 8, 2023 | Onedev is a self-hosted Git Server with CI/CD and Kanban. In versions prior to 7.9.12 the algorithm used to generate access token and password reset keys was not cryptographically secure. Existing normal users (or… |
| CVE-2022-38301 | High (8.8) | 1.4% | — | Sep 14, 2022 | Onedev v7.4.14 contains a path traversal vulnerability which allows attackers to access restricted files and directories via uploading a crafted JAR file into the directory /opt/onedev/lib. |
| CVE-2022-39208 | High (7.5) | 1.9% | — | Sep 13, 2022 | Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. All files in the /opt/onedev/sites/ directory are exposed and can be read by unauthenticated users. This directory contains all projects, including… |
| CVE-2022-39207 | Medium (5.4) | 1.0% | — | Sep 13, 2022 | Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. During CI/CD builds, it is possible to save build artifacts for later retrieval. They can be accessed through OneDev's web UI after the successful… |
| CVE-2022-39206 | Critical (9.9) | 2.1% | — | Sep 13, 2022 | Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. When using Docker-based job executors, the Docker socket (e.g. /var/run/docker.sock on Linux) is mounted into each Docker step. Users that can… |
| CVE-2022-39205 | Critical (9.8) | 2.4% | — | Sep 13, 2022 | Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. In versions of Onedev prior to 7.3.0 unauthenticated users can take over a OneDev instance if there is no properly configured reverse proxy. The… |
| CVE-2021-32651 | Medium (4.3) | 1.1% | — | Jun 1, 2021 | OneDev is a development operations platform. If the LDAP external authentication mechanism is enabled in OneDev versions 4.4.1 and prior, an attacker can manipulate a user search filter to send forged queries to the… |
| CVE-2021-21251 | High (8.8) | 13% | — | Jan 15, 2021 | OneDev is an all-in-one devops platform. In OneDev before version 4.0.3 there is a critical "zip slip" vulnerability. This issue may lead to arbitrary file write. The KubernetesResource REST endpoint untars user… |
| CVE-2021-21250 | Medium (6.5) | 0.93% | — | Jan 15, 2021 | OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which may lead to arbitrary file read. When BuildSpec is provided in XML format, the spec is processed by… |
| CVE-2021-21249 | High (8.8) | 2.9% | — | Jan 15, 2021 | OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is an issue involving YAML parsing which can lead to post-auth remote code execution. In order to parse and process YAML files, OneDev uses… |
| CVE-2021-21248 | High (8.8) | 1.5% | — | Jan 15, 2021 | OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability involving the build endpoint parameters. InputSpec is used to define parameters of a Build spec. It does so by… |
| CVE-2021-21247 | High (8.8) | 1.5% | — | Jan 15, 2021 | OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the application's BasePage registers an AJAX event listener (`AbstractPostAjaxBehavior`) in all pages other than the login page. This listener… |
| CVE-2021-21246 | High (7.5) | 49% | — | Jan 15, 2021 | OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the REST UserResource endpoint performs a security check to make sure that only administrators can list user details. However for the… |
| CVE-2021-21245 | Critical (9.8) | 1.2% | — | Jan 15, 2021 | OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, AttachmentUploadServlet also saves user controlled data (`request.getInputStream()`) to a user specified location… |
| CVE-2021-21242 | Critical (9.8) | 74% | — | Jan 15, 2021 | OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which can lead to pre-auth remote code execution. AttachmentUploadServlet deserializes untrusted data from the… |
| CVE-2021-21244 | Critical (9.8) | 1.5% | — | Jan 15, 2021 | OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, There is a vulnerability that enabled pre-auth server side template injection via Bean validation message tampering. Full details in the reference… |
| CVE-2021-21243 | Critical (9.8) | 54% | — | Jan 15, 2021 | OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, a Kubernetes REST endpoint exposes two methods that deserialize untrusted data from the request body. These endpoints do not enforce any… |