CVE-2021-21244
Dashboard / Vulnerabilities / CVE-2021-21244
Summary:
Details: OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, There is a vulnerability that enabled pre-auth server side template injection via Bean validation message tampering. Full details in the reference GHSA. This issue was fixed in 4.0.3 by disabling validation interpolation completely.
References: https://github.com/theonedev/onedev/security/advisories/GHSA-vm26-xg39-cfj4, https://github.com/theonedev/onedev/commit/4f5dc6fb9e50f2c41c4929b0d8c5824b2cca3d65
Affected packages
Package
Name:
Purl:
Affected ranges
Affected versions
v4.0.2
v4.0.1
v4.0.0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
