« Back to list

Onedev Project

Onedev Project Onedev: vulnerabilities and CVEs

Onedev Project Onedev has 18 published vulnerabilities, 0 of them in the last 12 months. 6 are rated critical and 0 are listed by CISA as actively exploited.

CVEs18
Last 12 months0
Critical6
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2024-45309High (8.7)25%—Oct 21, 2024
OneDev is a Git server with CI/CD, kanban, and packages. A vulnerability in versions prior to 11.0.9 allows unauthenticated users to read arbitrary files accessible by the OneDev server process. This issue has been…
CVE-2023-24828High (8.8)0.71%—Feb 8, 2023
Onedev is a self-hosted Git Server with CI/CD and Kanban. In versions prior to 7.9.12 the algorithm used to generate access token and password reset keys was not cryptographically secure. Existing normal users (or…
CVE-2022-38301High (8.8)1.4%—Sep 14, 2022
Onedev v7.4.14 contains a path traversal vulnerability which allows attackers to access restricted files and directories via uploading a crafted JAR file into the directory /opt/onedev/lib.
CVE-2022-39208High (7.5)1.9%—Sep 13, 2022
Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. All files in the /opt/onedev/sites/ directory are exposed and can be read by unauthenticated users. This directory contains all projects, including…
CVE-2022-39207Medium (5.4)1.0%—Sep 13, 2022
Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. During CI/CD builds, it is possible to save build artifacts for later retrieval. They can be accessed through OneDev's web UI after the successful…
CVE-2022-39206Critical (9.9)2.1%—Sep 13, 2022
Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. When using Docker-based job executors, the Docker socket (e.g. /var/run/docker.sock on Linux) is mounted into each Docker step. Users that can…
CVE-2022-39205Critical (9.8)2.4%—Sep 13, 2022
Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. In versions of Onedev prior to 7.3.0 unauthenticated users can take over a OneDev instance if there is no properly configured reverse proxy. The…
CVE-2021-32651Medium (4.3)1.1%—Jun 1, 2021
OneDev is a development operations platform. If the LDAP external authentication mechanism is enabled in OneDev versions 4.4.1 and prior, an attacker can manipulate a user search filter to send forged queries to the…
CVE-2021-21251High (8.8)13%—Jan 15, 2021
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3 there is a critical "zip slip" vulnerability. This issue may lead to arbitrary file write. The KubernetesResource REST endpoint untars user…
CVE-2021-21250Medium (6.5)0.93%—Jan 15, 2021
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which may lead to arbitrary file read. When BuildSpec is provided in XML format, the spec is processed by…
CVE-2021-21249High (8.8)2.9%—Jan 15, 2021
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is an issue involving YAML parsing which can lead to post-auth remote code execution. In order to parse and process YAML files, OneDev uses…
CVE-2021-21248High (8.8)1.5%—Jan 15, 2021
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability involving the build endpoint parameters. InputSpec is used to define parameters of a Build spec. It does so by…
CVE-2021-21247High (8.8)1.5%—Jan 15, 2021
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the application's BasePage registers an AJAX event listener (`AbstractPostAjaxBehavior`) in all pages other than the login page. This listener…
CVE-2021-21246High (7.5)49%—Jan 15, 2021
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the REST UserResource endpoint performs a security check to make sure that only administrators can list user details. However for the…
CVE-2021-21245Critical (9.8)1.2%—Jan 15, 2021
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, AttachmentUploadServlet also saves user controlled data (`request.getInputStream()`) to a user specified location…
CVE-2021-21242Critical (9.8)74%—Jan 15, 2021
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which can lead to pre-auth remote code execution. AttachmentUploadServlet deserializes untrusted data from the…
CVE-2021-21244Critical (9.8)1.5%—Jan 15, 2021
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, There is a vulnerability that enabled pre-auth server side template injection via Bean validation message tampering. Full details in the reference…
CVE-2021-21243Critical (9.8)54%—Jan 15, 2021
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, a Kubernetes REST endpoint exposes two methods that deserialize untrusted data from the request body. These endpoints do not enforce any…