Onedev Project

Onedev

18 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.3%
  • Veröffentlicht 15.01.2021 21:15:13
  • Zuletzt bearbeitet 21.11.2024 05:47:51

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is an issue involving YAML parsing which can lead to post-auth remote code execution. In order to parse and process YAML files, OneDev uses SnakeYaml which by default (whe...

  • EPSS 0.35%
  • Veröffentlicht 15.01.2021 21:15:13
  • Zuletzt bearbeitet 21.11.2024 05:47:51

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability involving the build endpoint parameters. InputSpec is used to define parameters of a Build spec. It does so by using dynamically generated Groo...

  • EPSS 0.31%
  • Veröffentlicht 15.01.2021 21:15:13
  • Zuletzt bearbeitet 21.11.2024 05:47:51

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the application's BasePage registers an AJAX event listener (`AbstractPostAjaxBehavior`) in all pages other than the login page. This listener decodes and deserializes the `data...

  • EPSS 27.14%
  • Veröffentlicht 15.01.2021 21:15:13
  • Zuletzt bearbeitet 21.11.2024 05:47:51

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the REST UserResource endpoint performs a security check to make sure that only administrators can list user details. However for the `/users/{id}` endpoint there are no securit...

  • EPSS 0.35%
  • Veröffentlicht 15.01.2021 21:15:13
  • Zuletzt bearbeitet 21.11.2024 05:47:51

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, AttachmentUploadServlet also saves user controlled data (`request.getInputStream()`) to a user specified location (`request.getHeader("File-Name")`). This issue may lead to arbi...

  • EPSS 40.37%
  • Veröffentlicht 15.01.2021 21:15:13
  • Zuletzt bearbeitet 21.11.2024 05:47:50

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which can lead to pre-auth remote code execution. AttachmentUploadServlet deserializes untrusted data from the `Attachment-Support` header. Thi...

  • EPSS 2.51%
  • Veröffentlicht 15.01.2021 20:15:12
  • Zuletzt bearbeitet 21.11.2024 05:47:51

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, a Kubernetes REST endpoint exposes two methods that deserialize untrusted data from the request body. These endpoints do not enforce any authentication or authorization checks. ...

  • EPSS 0.39%
  • Veröffentlicht 15.01.2021 20:15:12
  • Zuletzt bearbeitet 21.11.2024 05:47:51

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, There is a vulnerability that enabled pre-auth server side template injection via Bean validation message tampering. Full details in the reference GHSA. This issue was fixed in ...