PT-2024-7509 · Onedev · Onedev
Robinshine
·
Published
2024-08-26
·
Updated
2025-01-13
·
CVE-2024-45309
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
OneDev versions prior to 11.0.9
Description:
A vulnerability in OneDev allows unauthenticated users to read arbitrary files accessible by the OneDev server process. This issue has been fixed in version 11.0.9. The vulnerability is related to insufficient protection of internal data, which could allow a remote attacker to read arbitrary files, potentially exposing sensitive information.
Recommendations:
For versions prior to 11.0.9, update to version 11.0.9 to patch this issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation. Avoid using the OneDev server process to access sensitive files until the issue is resolved.
Exploit
Fix
Path traversal
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Onedev