PT-2023-19809 · Onedev · Onedev

Emilytrau

+1

·

Published

2023-02-07

·

Updated

2023-02-16

·

CVE-2023-24828

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Onedev versions prior to 7.9.12
Description Onedev is a self-hosted Git Server with CI/CD and Kanban. The algorithm used to generate access token and password reset keys was not cryptographically secure in versions prior to 7.9.12. Existing normal users, or everyone if self-registration is allowed, may exploit this to elevate their privilege and obtain administrator permission.
Recommendations For versions prior to 7.9.12, upgrade to version 7.9.12 to address the issue. As a temporary workaround, consider restricting self-registration and closely monitoring user activities until the upgrade is applied. There are no known workarounds for this issue other than upgrading to the fixed version.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2023-24828
GHSA-JF5C-9R77-3J5J

Affected Products

Onedev