PT-2022-24808 · Onedev · Onedev
Paul Gerste
·
Published
2022-09-13
·
Updated
2022-10-01
·
CVE-2022-39208
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Onedev versions prior to 7.3.0
Description
Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. All files in the
/opt/onedev/sites/ directory are exposed and can be read by unauthenticated users. This directory contains all projects, including their bare git repos and build artifacts. This issue can be used by unauthenticated attackers to leak all project files of any project. Since project IDs are incremental, an attacker could iterate through them and leak all project data.Recommendations
For versions prior to 7.3.0, upgrade to version 7.3.0 to resolve the issue. As a temporary workaround, consider restricting access to the
/opt/onedev/sites/ directory until the upgrade is applied.Exploit
Fix
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Onedev