VendorsOneDev Projectonedevall versions
Vulnerabilities

OneDev Project OneDev

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18CVEs
CVE-2021-21242
Pre-Auth Unsafe Deserialization on AttachmentUploadServet
Published 2021-01-15 · Modified
10.0EPSS 0.742
CVE-2021-21243
Pre-Auth Unsafe Deserialization on KubernetesResource
Published 2021-01-15 · Modified
10.0EPSS 0.545
CVE-2021-21244
Pre-Auth SSTI via Bean validation message tampering
Published 2021-01-15 · Modified
10.0EPSS 0.015
CVE-2021-21245
Pre-Auth Arbitrary File Upload
Published 2021-01-15 · Modified
10.0EPSS 0.012
CVE-2022-39206
CI/CD Docker Escape in OneDev
Published 2022-09-13 · Modified
9.9EPSS 0.021
CVE-2022-39205
Access Control Bypass in Onedev
Published 2022-09-13 · Modified
9.8EPSS 0.024
CVE-2021-21249
Post-Auth Unsafe Yaml deserialization
Published 2021-01-15 · Modified
9.6EPSS 0.029
CVE-2021-21247
Post-Auth Unsafe Deserialization on BasePage (AJAX)
Published 2021-01-15 · Modified
9.6EPSS 0.015
CVE-2021-21248
Post-Auth Arbitrary Code execution via Groovy script injection
Published 2021-01-15 · Modified
9.6EPSS 0.015
CVE-2021-21251
ZipSlip Arbitrary File Upload
Published 2021-01-15 · Modified
8.8EPSS 0.127
CVE-2022-38301
Onedev v7.4.14 contains a path traversal vulnerability which allows attackers to access restricted files and directories via uploading a crafted JAR file into the directory /opt/onedev/lib.
Published 2022-09-14 · Modified
8.8EPSS 0.014
CVE-2023-24828
Use of Cryptographically Weak Pseudo-Random Number Generator in Onedev
Published 2023-02-07 · Modified
8.8EPSS 0.007
CVE-2024-45309
OneDev vulnerable to arbitrary file reading for unauthenticated user
Published 2024-10-21 · Analyzed
8.7EPSS 0.245
CVE-2021-21246
Pre-Auth Access token leak
Published 2021-01-15 · Modified
8.6EPSS 0.491
CVE-2021-21250
Post-Auth External Entity Expansion (XXE)
Published 2021-01-15 · Modified
7.7EPSS 0.009
CVE-2022-39208
Git Repository Disclosure in Onedev
Published 2022-09-13 · Modified
7.5EPSS 0.019
CVE-2022-39207
Persistent XSS in OneDev
Published 2022-09-13 · Modified
5.4EPSS 0.010
CVE-2021-32651
LDAP injection via OneDev may leak some LDAP directory information
Published 2021-06-01 · Modified
4.3EPSS 0.011