PT-2023-19809 · Onedev · Onedev
Emilytrau
+1
·
Published
2023-02-07
·
Updated
2023-02-16
·
CVE-2023-24828
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Onedev versions prior to 7.9.12
Description
Onedev is a self-hosted Git Server with CI/CD and Kanban. The algorithm used to generate access token and password reset keys was not cryptographically secure in versions prior to 7.9.12. Existing normal users, or everyone if self-registration is allowed, may exploit this to elevate their privilege and obtain administrator permission.
Recommendations
For versions prior to 7.9.12, upgrade to version 7.9.12 to address the issue. As a temporary workaround, consider restricting self-registration and closely monitoring user activities until the upgrade is applied. There are no known workarounds for this issue other than upgrading to the fixed version.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Onedev