📦 Onedev

by Onedev Project

🔍 What is Onedev?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-21242

CRITICAL CVSS 10.0 Jan 15, 2021

CVE-2021-21242 is a critical pre-authentication remote code execution vulnerability in OneDev devops platform. Attackers can exploit insecure deserialization in AttachmentUploadServlet to execute arbi...

CVE-2021-21247

CRITICAL CVSS 9.6 Jan 15, 2021

This vulnerability allows authenticated attackers to achieve remote code execution on OneDev DevOps platforms by exploiting insecure deserialization in AJAX event listeners. It affects all OneDev inst...

CVE-2021-21249

CRITICAL CVSS 9.6 Jan 15, 2021

CVE-2021-21249 is a post-authentication remote code execution vulnerability in OneDev DevOps platform. It allows authenticated attackers to execute arbitrary code on the server by exploiting insecure ...

CVE-2021-21243

CRITICAL CVSS 10.0 Jan 15, 2021

This vulnerability in OneDev allows unauthenticated remote code execution via insecure deserialization in Kubernetes REST endpoints. Attackers can exploit this to execute arbitrary code on affected sy...

CVE-2023-24828

HIGH CVSS 8.1 Feb 8, 2023

CVE-2023-24828 is a cryptographic weakness in OneDev's access token and password reset key generation algorithm that allows normal users to predict or brute-force administrative credentials. This affe...