CVE-2021-21249
- EPSS 1.3%
- Veröffentlicht 15.01.2021 21:15:13
- Zuletzt bearbeitet 21.11.2024 05:47:51
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is an issue involving YAML parsing which can lead to post-auth remote code execution. In order to parse and process YAML files, OneDev uses SnakeYaml which by default (whe...
CVE-2021-21248
- EPSS 0.35%
- Veröffentlicht 15.01.2021 21:15:13
- Zuletzt bearbeitet 21.11.2024 05:47:51
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability involving the build endpoint parameters. InputSpec is used to define parameters of a Build spec. It does so by using dynamically generated Groo...
CVE-2021-21247
- EPSS 0.31%
- Veröffentlicht 15.01.2021 21:15:13
- Zuletzt bearbeitet 21.11.2024 05:47:51
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the application's BasePage registers an AJAX event listener (`AbstractPostAjaxBehavior`) in all pages other than the login page. This listener decodes and deserializes the `data...
CVE-2021-21246
- EPSS 27.14%
- Veröffentlicht 15.01.2021 21:15:13
- Zuletzt bearbeitet 21.11.2024 05:47:51
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the REST UserResource endpoint performs a security check to make sure that only administrators can list user details. However for the `/users/{id}` endpoint there are no securit...
CVE-2021-21245
- EPSS 0.35%
- Veröffentlicht 15.01.2021 21:15:13
- Zuletzt bearbeitet 21.11.2024 05:47:51
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, AttachmentUploadServlet also saves user controlled data (`request.getInputStream()`) to a user specified location (`request.getHeader("File-Name")`). This issue may lead to arbi...
CVE-2021-21242
- EPSS 40.37%
- Veröffentlicht 15.01.2021 21:15:13
- Zuletzt bearbeitet 21.11.2024 05:47:50
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which can lead to pre-auth remote code execution. AttachmentUploadServlet deserializes untrusted data from the `Attachment-Support` header. Thi...
CVE-2021-21243
- EPSS 2.51%
- Veröffentlicht 15.01.2021 20:15:12
- Zuletzt bearbeitet 21.11.2024 05:47:51
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, a Kubernetes REST endpoint exposes two methods that deserialize untrusted data from the request body. These endpoints do not enforce any authentication or authorization checks. ...
CVE-2021-21244
- EPSS 0.39%
- Veröffentlicht 15.01.2021 20:15:12
- Zuletzt bearbeitet 21.11.2024 05:47:51
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, There is a vulnerability that enabled pre-auth server side template injection via Bean validation message tampering. Full details in the reference GHSA. This issue was fixed in ...