Onedev Project

Onedev

18 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 87.64%
  • Veröffentlicht 21.10.2024 15:15:03
  • Zuletzt bearbeitet 14.11.2024 19:39:31

OneDev is a Git server with CI/CD, kanban, and packages. A vulnerability in versions prior to 11.0.9 allows unauthenticated users to read arbitrary files accessible by the OneDev server process. This issue has been fixed in version 11.0.9.

  • EPSS 0.3%
  • Veröffentlicht 08.02.2023 00:15:08
  • Zuletzt bearbeitet 21.11.2024 07:48:28

Onedev is a self-hosted Git Server with CI/CD and Kanban. In versions prior to 7.9.12 the algorithm used to generate access token and password reset keys was not cryptographically secure. Existing normal users (or everyone if it allows self-registrat...

Exploit
  • EPSS 0.61%
  • Veröffentlicht 14.09.2022 21:15:10
  • Zuletzt bearbeitet 21.11.2024 07:16:12

Onedev v7.4.14 contains a path traversal vulnerability which allows attackers to access restricted files and directories via uploading a crafted JAR file into the directory /opt/onedev/lib.

Exploit
  • EPSS 0.78%
  • Veröffentlicht 13.09.2022 19:15:13
  • Zuletzt bearbeitet 21.11.2024 07:17:47

Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. All files in the /opt/onedev/sites/ directory are exposed and can be read by unauthenticated users. This directory contains all projects, including their bare git repos and build...

Exploit
  • EPSS 0.47%
  • Veröffentlicht 13.09.2022 19:15:13
  • Zuletzt bearbeitet 21.11.2024 07:17:47

Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. During CI/CD builds, it is possible to save build artifacts for later retrieval. They can be accessed through OneDev's web UI after the successful run of a build. These artifact ...

Exploit
  • EPSS 1.41%
  • Veröffentlicht 13.09.2022 19:15:13
  • Zuletzt bearbeitet 21.11.2024 07:17:47

Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. When using Docker-based job executors, the Docker socket (e.g. /var/run/docker.sock on Linux) is mounted into each Docker step. Users that can define and trigger CI/CD jobs on a ...

Exploit
  • EPSS 3.22%
  • Veröffentlicht 13.09.2022 19:15:13
  • Zuletzt bearbeitet 21.11.2024 07:17:46

Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. In versions of Onedev prior to 7.3.0 unauthenticated users can take over a OneDev instance if there is no properly configured reverse proxy. The /git-prereceive-callback endpoint...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 01.06.2021 18:15:07
  • Zuletzt bearbeitet 21.11.2024 06:07:27

OneDev is a development operations platform. If the LDAP external authentication mechanism is enabled in OneDev versions 4.4.1 and prior, an attacker can manipulate a user search filter to send forged queries to the application and explore the LDAP t...

  • EPSS 0.71%
  • Veröffentlicht 15.01.2021 21:15:13
  • Zuletzt bearbeitet 21.11.2024 05:47:51

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3 there is a critical "zip slip" vulnerability. This issue may lead to arbitrary file write. The KubernetesResource REST endpoint untars user controlled data from the request body ...

  • EPSS 0.29%
  • Veröffentlicht 15.01.2021 21:15:13
  • Zuletzt bearbeitet 21.11.2024 05:47:51

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which may lead to arbitrary file read. When BuildSpec is provided in XML format, the spec is processed by XmlBuildSpecMigrator.migrate(buildSpe...