CVE-2021-21244

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-21244
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-21244.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-21244
Related
  • GHSA-vm26-xg39-cfj4
Published
2021-01-15T20:15:12Z
Modified
2025-01-15T01:47:14.455097Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, There is a vulnerability that enabled pre-auth server side template injection via Bean validation message tampering. Full details in the reference GHSA. This issue was fixed in 4.0.3 by disabling validation interpolation completely.

References

Affected packages

Git / github.com/theonedev/onedev

Affected ranges

Type
GIT
Repo
https://github.com/theonedev/onedev
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

2.*

2.0-beta-build118
2.0-beta-build119
2.0-beta-build120
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6

v3.*

v3.0.10
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9