CVE-2023-24828

Source
https://cve.org/CVERecord?id=CVE-2023-24828
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-24828.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-24828
Aliases
  • GHSA-jf5c-9r77-3j5j
Published
2023-02-07T23:25:11.397Z
Modified
2026-08-08T08:45:25.790609Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
Use of Cryptographically Weak Pseudo-Random Number Generator in Onedev
Details

Onedev is a self-hosted Git Server with CI/CD and Kanban. In versions prior to 7.9.12 the algorithm used to generate access token and password reset keys was not cryptographically secure. Existing normal users (or everyone if it allows self-registration) may exploit this to elevate privilege to obtain administrator permission. This issue is has been addressed in version 7.9.12. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Database specific
{
    "cwe_ids": [
        "CWE-338"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/24xxx/CVE-2023-24828.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/theonedev/onedev

Affected ranges

Type
GIT
Repo
https://github.com/theonedev/onedev
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "cpe": "cpe:2.3:a:onedev_project:onedev:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "7.9.12"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

2.*
2.0-beta-build119
2.0-beta-build120
2.0.0
2.0.4
2.0.5
v3.*
v3.0.10
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.1.0
v3.1.1
v3.1.2
v3.2.0
v3.2.1
v3.2.2
v3.2.3
v3.2.4
v4.*
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.2
v4.1.3
v4.1.4
v4.1.5
v4.1.6
v4.10.3
v4.11.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.3.0
v4.3.2
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.6.0
v4.6.1
v4.7.0
v4.8.0
v4.8.1
v4.9.0
v4.9.1
v4.9.2
v5.*
v5.0.0
v5.0.1
v5.1.0
v5.2.0
v5.2.1
v5.2.2
v5.3.0
v5.3.1
v5.3.3
v5.4.0
v6.*
v6.0.0
v6.1.0
v6.1.1
v6.1.2
v6.1.3
v6.1.4
v6.2.0
v6.2.1
v6.2.2
v6.2.3
v6.2.4
v6.3.0
v6.3.1
v6.3.10
v6.3.11
v6.3.12
v6.3.13
v6.3.2
v6.3.3
v6.3.4
v6.3.5
v6.3.6
v6.3.7
v6.3.8
v6.3.9
v7.*
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.1.0
v7.1.1
v7.1.2
v7.1.3
v7.1.6
v7.1.7
v7.1.8
v7.2.0
v7.2.1
v7.2.2
v7.2.3
v7.2.4
v7.2.5
v7.2.7
v7.2.8
v7.2.9
v7.3.0
v7.3.10
v7.3.11
v7.3.12
v7.3.13
v7.3.14
v7.3.15
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.6
v7.3.7
v7.3.8
v7.3.9
v7.4.0
v7.4.1
v7.4.10
v7.4.11
v7.4.12
v7.4.13
v7.4.14
v7.4.15
v7.4.16
v7.4.17
v7.4.18
v7.4.19
v7.4.2
v7.4.20
v7.4.21
v7.4.22
v7.4.23
v7.4.24
v7.4.25
v7.4.26
v7.4.27
v7.4.28
v7.4.29
v7.4.3
v7.4.7
v7.4.8
v7.4.9
v7.5.0
v7.5.1
v7.5.2
v7.5.3
v7.6.0
v7.6.1
v7.6.2
v7.7.1
v7.7.12
v7.7.13
v7.7.14
v7.7.2
v7.7.5
v7.8.0
v7.8.1
v7.8.10
v7.8.11
v7.8.12
v7.8.13
v7.8.14
v7.8.15
v7.8.2
v7.8.3
v7.8.4
v7.8.5
v7.8.6
v7.8.7
v7.8.8
v7.8.9
v7.9.0
v7.9.1
v7.9.10
v7.9.11
v7.9.2
v7.9.3
v7.9.4
v7.9.5
v7.9.6
v7.9.7
v7.9.8
v7.9.9

Database specific

vanir_signatures_modified
"2026-08-08T08:45:25Z"
vanir_signatures
[
    {
        "id": "CVE-2023-24828-016ab3fb",
        "deprecated": false,
        "signature_type": "Function",
        "signature_version": "v1",
        "digest": {
            "length": 6166.0,
            "function_hash": "205644080855310684102357847310457983102"
        },
        "source": "https://github.com/theonedev/onedev/commit/d67dd9686897fe5e4ab881d749464aa7c06a68e5",
        "target": {
            "function": "migrate42",
            "file": "server-core/src/main/java/io/onedev/server/migration/DataMigrator.java"
        }
    },
    {
        "id": "CVE-2023-24828-021dbb3b",
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "34484454488243352717750711315569175014",
                "229359184494163523666988360693782983111",
                "102291823583598711204964891994534802666",
                "43417544776756315122099716252703733916",
                "197396007464406695420858196674614471793",
                "220410120081942762092591612855512989072",
                "294423291940624074875763269268694802898",
                "40623071868608862431337848979763999618",
                "339683333482091597079855535613279323032",
                "321610573393082491980696802366410773605",
                "163670710514798590488053256424086377996",
                "106385733045310555965589007383923676902",
                "172771449018414888238778013641063754835",
                "123938636046410299237985296877524582813",
                "272914615851064708884367586021243135924",
                "6179403917109183941692036988559036120",
                "266290927866971724513030063662362460883",
                "11718980548304050182706722193632128311",
                "91646879048940189185801653980348186433",
                "146080327270907132170441829022185446357",
                "151317106491456138052173874619277170837",
                "126600139303017718641279701140991625577",
                "181702028395338403450882155218435660229",
                "73528474828997915968482106158585814662",
                "213551636604050895341307947806187569675",
                "120913587746109617473066267811545336543",
                "224185713401925760813188011174893491202",
                "109348407894873665603857671679636004327",
                "50655010624260041168324677530280507777"
            ]
        },
        "source": "https://github.com/theonedev/onedev/commit/d67dd9686897fe5e4ab881d749464aa7c06a68e5",
        "target": {
            "file": "server-core/src/main/java/io/onedev/server/web/component/user/twofactorauthentication/TwoFactorAuthenticationSetupPanel.java"
        }
    },
    {
        "id": "CVE-2023-24828-08f1c130",
        "deprecated": false,
        "signature_type": "Function",
        "signature_version": "v1",
        "digest": {
            "length": 270.0,
            "function_hash": "200673137273799621725310979164570200952"
        },
        "source": "https://github.com/theonedev/onedev/commit/d67dd9686897fe5e4ab881d749464aa7c06a68e5",
        "target": {
            "function": "onClick",
            "file": "server-core/src/main/java/io/onedev/server/web/component/user/accesstoken/AccessTokenPanel.java"
        }
    },
    {
        "id": "CVE-2023-24828-133e2e36",
        "deprecated": false,
        "signature_type": "Function",
        "signature_version": "v1",
        "digest": {
            "length": 2137.0,
            "function_hash": "11818508855085637785465204100743596138"
        },
        "source": "https://github.com/theonedev/onedev/commit/d67dd9686897fe5e4ab881d749464aa7c06a68e5",
        "target": {
            "function": "onSubmit",
            "file": "server-core/src/main/java/io/onedev/server/web/component/user/twofactorauthentication/TwoFactorAuthenticationSetupPanel.java"
        }
    },
    {
        "id": "CVE-2023-24828-137404f4",
        "deprecated": false,
        "signature_type": "Function",
        "signature_version": "v1",
        "digest": {
            "length": 4183.0,
            "function_hash": "70290041221264755430897412234928302965"
        },
        "source": "https://github.com/theonedev/onedev/commit/d67dd9686897fe5e4ab881d749464aa7c06a68e5",
        "target": {
            "function": "onInitialize",
            "file": "server-core/src/main/java/io/onedev/server/web/component/user/twofactorauthentication/TwoFactorAuthenticationSetupPanel.java"
        }
    },
    {
        "id": "CVE-2023-24828-17a3ef70",
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "177764437201945390179223639666732076528",
                "100302413421921315724805699748891053550",
                "97350511054758052474736737181252517329",
                "209362730421488110502975992075364317896",
                "2141288207664452665160724541518860624",
                "252409487546928585634370106875482447332",
                "302072053231689020830669538431630448625",
                "140671493421435258992437772930769191729",
                "191254756534871233087591770955718767251",
                "107434941686097280743950816858010711124",
                "175234468212896337322377901631196769034",
                "197583027913346035283572766043648698930",
                "163227938343914575654963203425253583451",
                "185567622523633668038083005290758537386",
                "3353534947509643654441781636694763275",
                "175948178036973690728391420362457259059",
                "137499332656107079325547794008816369020",
                "266921783618390337815477893966027850073",
                "144648003389493172336123538218421645516",
                "14467480352664649163615344117081043630",
                "223406457339365569623065686624098041561",
                "117271702538925995151676966482261260358",
                "294138466007231446196995473133566039210"
            ]
        },
        "source": "https://github.com/theonedev/onedev/commit/d67dd9686897fe5e4ab881d749464aa7c06a68e5",
        "target": {
            "file": "server-core/src/main/java/io/onedev/server/web/page/simple/security/PasswordResetPage.java"
        }
    },
    {
        "id": "CVE-2023-24828-1d49610f",
        "deprecated": false,
        "signature_type": "Function",
        "signature_version": "v1",
        "digest": {
            "length": 3492.0,
            "function_hash": "151390395787979756279804736280593249887"
        },
        "source": "https://github.com/theonedev/onedev/commit/d67dd9686897fe5e4ab881d749464aa7c06a68e5",
        "target": {
            "function": "onInitialize",
            "file": "server-core/src/main/java/io/onedev/server/web/page/simple/security/PasswordResetPage.java"
        }
    },
    {
        "id": "CVE-2023-24828-26412f8f",
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "120325696979703866886242223522695076050",
                "4835940929587297382105392076220116011",
                "159895289079858372418830760583312579266",
                "240435539310969295819496526640967858011",
                "264460501872395599063062705503683467450",
                "207919467657263251630527384292475501073",
                "142120722575460236454927179090374698310",
                "161284747964642532489034542597982868876",
                "55058152113087099252361130701163145953",
                "152400974919847919328241973501685141126",
                "220484778630974659089977783578564156936",
                "145911561703446892153572005484744624991",
                "27368387877645536707498772870906902514",
                "328835782034823190592971359106029398043",
                "302352263547832853761759709330737598884",
                "67180782223523551373959495859159225319",
                "140281292366819176423548293400014894943"
            ]
        },
        "source": "https://github.com/theonedev/onedev/commit/d67dd9686897fe5e4ab881d749464aa7c06a68e5",
        "target": {
            "file": "server-core/src/main/java/io/onedev/server/util/CryptoUtils.java"
        }
    },
    {
        "id": "CVE-2023-24828-38a68077",
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "146538345130655479313745337465723298479",
                "91134726553060950099754829623832445747",
                "102683363508703635955932099291259446469",
                "178969120777820393104917866268749621942",
                "165271520091876261626861876658774552831",
                "84816632906070665815479476103998119954",
                "209188232643315345774891830434651955045",
                "87695552258930848151201683169184621040",
                "192476825459188440351584040411886459408",
                "152376838027711075988136317153678657297",
                "9670685447431117301143376117009887956",
                "175541998395662634578550502293003764058",
                "226296152265928731873051605019932934795",
                "199496491459216903969708405216979941355"
            ]
        },
        "source": "https://github.com/theonedev/onedev/commit/d67dd9686897fe5e4ab881d749464aa7c06a68e5",
        "target": {
            "file": "server-core/src/main/java/io/onedev/server/web/component/user/accesstoken/AccessTokenPanel.java"
        }
    },
    {
        "id": "CVE-2023-24828-38b3c79c",
        "deprecated": false,
        "signature_type": "Function",
        "signature_version": "v1",
        "digest": {
            "length": 2047.0,
            "function_hash": "184204300039882084969941095682678218254"
        },
        "source": "https://github.com/theonedev/onedev/commit/d67dd9686897fe5e4ab881d749464aa7c06a68e5",
        "target": {
            "function": "runTask",
            "file": "server-core/src/main/java/io/onedev/server/web/page/simple/security/PasswordResetPage.java"
        }
    },
    {
        "id": "CVE-2023-24828-43a3b34f",
        "deprecated": false,
        "signature_type": "Function",
        "signature_version": "v1",
        "digest": {
            "length": 6766.0,
            "function_hash": "88132188824833095364556984515090065646"
        },
        "source": "https://github.com/theonedev/onedev/commit/d67dd9686897fe5e4ab881d749464aa7c06a68e5",
        "target": {
            "function": "migrate61",
            "file": "server-core/src/main/java/io/onedev/server/migration/DataMigrator.java"
        }
    },
    {
        "id": "CVE-2023-24828-46fa6479",
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "225375412423285825617687936201107615123",
                "45031369314050861611499735077801701443",
                "25275282854804608289654040031519073705",
                "264931406496443481743619368397679011863",
                "198846947713226510858858024886260911547",
                "30909699846842807179336112607475263489",
                "174762521791483107887231509080532556213",
                "250083373923668930411074703068787458062",
                "165290625325165146201795326474453680365",
                "102732063557782669303068303083672251991",
                "115615077903536387082985001417579971981",
                "298025792602659397589992361309656224332",
                "297248380518540713765726075167768148050",
                "150001471303708585357196285856886546568",
                "33649583210198742537140472367912268884",
                "75519113499305573011480473616434120442",
                "108587633537507210242609878158511307392"
            ]
        },
        "source": "https://github.com/theonedev/onedev/commit/d67dd9686897fe5e4ab881d749464aa7c06a68e5",
        "target": {
            "file": "server-core/src/main/java/io/onedev/server/migration/DataMigrator.java"
        }
    },
    {
        "id": "CVE-2023-24828-491c804b",
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "54841453196833303586020376490012654665",
                "123200737394920229034500833127712777830",
                "10040136998227364996142417441746759235",
                "33487381766960100926845891121321767597",
                "90523533681461266110891543154068924904",
                "300678681198505433626458894321723225942",
                "37352866617825232954479189842565634193",
                "299799257468717975386301430304788349883",
                "245207629934948213923643255633982363767",
                "32757326646635933426914248392805537043",
                "92975286427359610063205953028137690318",
                "166260761817065949968064190471256408555",
                "51105458133381032654968176439723293846",
                "284085809605966718783946009879887852706",
                "130325686575762213250628145711078183114",
                "276666413549074793414454271912638297224",
                "147713836534490340682137882678307837780"
            ]
        },
        "source": "https://github.com/theonedev/onedev/commit/d67dd9686897fe5e4ab881d749464aa7c06a68e5",
        "target": {
            "file": "server-core/src/main/java/io/onedev/server/model/support/WebHook.java"
        }
    },
    {
        "id": "CVE-2023-24828-5def0173",
        "deprecated": false,
        "signature_type": "Function",
        "signature_version": "v1",
        "digest": {
            "length": 864.0,
            "function_hash": "27682102015994394292676446314770008102"
        },
        "source": "https://github.com/theonedev/onedev/commit/d67dd9686897fe5e4ab881d749464aa7c06a68e5",
        "target": {
            "function": "onInitialize",
            "file": "server-core/src/main/java/io/onedev/server/web/component/user/accesstoken/AccessTokenPanel.java"
        }
    },
    {
        "id": "CVE-2023-24828-d0b7815e",
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "120943872946505472517979859139232074985",
                "136041384901830033236921831392598050878",
                "282059101450594594506219373344056818606",
                "114780353745837864563401920571445365013",
                "68019595721108316193488295784747419471",
                "27226061535685454048945301589554594134",
                "76716397248608244372497547971501958474",
                "253832037942233174538365289039513558348",
                "319371527485638372367616144621169330720",
                "87452209293233341415769543728401830832",
                "306152618031706462500072763031080003911",
                "282001751463913035441685070937913894798",
                "305798657539907431638611280286474860063",
                "98869367167721218294199920988164910030",
                "324047794449643267183185660744351778499",
                "265072968710540690738466996145116176480",
                "305458457479236278197607039101383341471",
                "127792966403577194419785287483091987016",
                "193664813046255475156855774963050377278",
                "131508632018055685007503525934721351258"
            ]
        },
        "source": "https://github.com/theonedev/onedev/commit/d67dd9686897fe5e4ab881d749464aa7c06a68e5",
        "target": {
            "file": "server-core/src/main/java/io/onedev/server/model/EmailAddress.java"
        }
    },
    {
        "id": "CVE-2023-24828-f266badb",
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "77448481555953926368552706514672125998",
                "128903784236150024561680478568938700635",
                "34468840235018734983526440725461515409",
                "298789914074936547252608159027416153113",
                "84232482081658931895994273351542911388",
                "317516201919861886508009709716532310752",
                "58115129252570103160654067830323067193",
                "168006546462740266275050937333138062520",
                "38695559485711764093758827014276298123",
                "262737889451691028118514429893852204742",
                "239753388689269346725232802738767494327",
                "237897188275560065188319701855631844073",
                "207278177611986515056010806726412556569",
                "250420042290421474625241858803453014663",
                "218526678742962450941955966828080868827",
                "276038346803354794945742693849631518406",
                "296935002427980317814981536989540057882"
            ]
        },
        "source": "https://github.com/theonedev/onedev/commit/d67dd9686897fe5e4ab881d749464aa7c06a68e5",
        "target": {
            "file": "server-core/src/main/java/io/onedev/server/git/hook/HookUtils.java"
        }
    },
    {
        "id": "CVE-2023-24828-f8ec777b",
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "142467036512825116418517604602569569254",
                "62640144313424347706800916951843156059",
                "28419970155381762999991334389173020064",
                "308845511669724303989246774150627081988",
                "4189556169288211909373983332580260354",
                "198605363911037618170318576321344986122",
                "6320549534345276462169339939129960708",
                "58404570089824029138921605959315900740",
                "185430097771420980438277116055605408420",
                "48592873438451391366319143609206713242",
                "293559114017248857265427773313810414433",
                "129661150278783117044424672117700864267",
                "111524956893454479396902508484256424388",
                "128548066215904714728215229799024545650",
                "28365910838151882289814576533696453045",
                "242105709852794069252846040869076036106",
                "320674012911039641259830196151464939772",
                "155701283237715769548314414326256590036",
                "137381725236383815738345483280936439557",
                "234158497749718234535496667050821751192",
                "46270311382451539636603156894914646022",
                "231123291780480607477459515454466672253",
                "168147460002991728094456699989963202234",
                "213388580542165691857047322645066693836",
                "121730398262773760112370303256500073916",
                "253260225186203569596548183602754084842",
                "146083765597706692415761244492496548086",
                "298175813493169608170779091767383707372",
                "302592969021410412396250728288228630154",
                "50410454057803868069858134550403773053",
                "338685926479294039912447008740797509504",
                "216616436967139813192065804894410492249",
                "308041041563548006067029534614707798702",
                "326139865137504693876801258978996985192",
                "319738633706636684155178904474269117664",
                "254542626390085219664092617956179157974",
                "62069688170786622902457584330038335511",
                "69541203825609850909362364634962070639",
                "149957326085092462914287598161961483887",
                "217587319762717093134539493814683656552",
                "152375755749742210086564265813584490584",
                "155443473577965534797412235814580414287",
                "289898773119947001303999631959056410869",
                "118813076331454664459940972752903816719",
                "171815099669541950988873376706285180548",
                "27206459051874309946856097190770714419",
                "223799374237038458370876218187207488999",
                "284906625032902930870689139399757182814",
                "32132402982507824972757103469556300102",
                "207272119184774523666972679800530080543"
            ]
        },
        "source": "https://github.com/theonedev/onedev/commit/d67dd9686897fe5e4ab881d749464aa7c06a68e5",
        "target": {
            "file": "server-core/src/main/java/io/onedev/server/model/User.java"
        }
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-24828.json"