PT-2021-14354 · Onedev · Onedev

Pwntester

·

Published

2021-01-15

·

Updated

2022-10-19

·

CVE-2021-21244

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: OneDev versions prior to 4.0.3
Description: The issue is related to a pre-auth server side template injection via Bean validation message tampering in OneDev, an all-in-one devops platform. This was fixed in version 4.0.3 by disabling validation interpolation completely.
Recommendations: For versions prior to 4.0.3, update to version 4.0.3 or later to resolve the issue by having validation interpolation disabled. As a temporary workaround, consider disabling validation interpolation completely until the update can be applied.

Fix

Code Injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2021-21244
GHSA-VM26-XG39-CFJ4

Affected Products

Onedev