PT-2021-14354 · Onedev · Onedev
Pwntester
·
Published
2021-01-15
·
Updated
2022-10-19
·
CVE-2021-21244
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
OneDev versions prior to 4.0.3
Description:
The issue is related to a pre-auth server side template injection via Bean validation message tampering in OneDev, an all-in-one devops platform. This was fixed in version 4.0.3 by disabling validation interpolation completely.
Recommendations:
For versions prior to 4.0.3, update to version 4.0.3 or later to resolve the issue by having validation interpolation disabled. As a temporary workaround, consider disabling validation interpolation completely until the update can be applied.
Fix
Code Injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Onedev