CVE-2021-21242
Dashboard / Vulnerabilities / CVE-2021-21242
Summary:
Details: OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which can lead to pre-auth remote code execution. AttachmentUploadServlet deserializes untrusted data from the `Attachment-Support` header. This Servlet does not enforce any authentication or authorization checks. This issue may lead to pre-auth remote code execution. This issue was fixed in 4.0.3 by removing AttachmentUploadServlet and not using deserialization
References: https://github.com/theonedev/onedev/security/advisories/GHSA-5q3q-f373-2jv8, https://github.com/theonedev/onedev/commit/f864053176c08f59ef2d97fea192ceca46a4d9be
Affected packages
Package
Name:
Purl:
Affected ranges
Affected versions
v4.0.2
v4.0.1
v4.0.0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
