PT-2023-19809 · Onedev · Onedev

Emilytrau

+1

·

Publicado

2023-02-07

·

Atualizado

2023-02-16

·

CVE-2023-24828

CVSS v3.1

8.1

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Onedev versions prior to 7.9.12
Description Onedev is a self-hosted Git Server with CI/CD and Kanban. The algorithm used to generate access token and password reset keys was not cryptographically secure in versions prior to 7.9.12. Existing normal users, or everyone if self-registration is allowed, may exploit this to elevate their privilege and obtain administrator permission.
Recommendations For versions prior to 7.9.12, upgrade to version 7.9.12 to address the issue. As a temporary workaround, consider restricting self-registration and closely monitoring user activities until the upgrade is applied. There are no known workarounds for this issue other than upgrading to the fixed version.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-24828
GHSA-JF5C-9R77-3J5J

Produtos afetados

Onedev