OneDev is a Git server with CI/CD, kanban, and packages. A vulnerability in versions prior to 11.0.9 allows unauthenticated users to read arbitrary files accessible by the OneDev server process. This issue has been fixed in version 11.0.9.
Metrics
Affected Vendors & Products
References
History
Thu, 14 Nov 2024 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Onedev Project
Onedev Project onedev |
|
Weaknesses | CWE-22 | |
CPEs | cpe:2.3:a:onedev_project:onedev:*:*:*:*:*:*:*:* | |
Vendors & Products |
Onedev Project
Onedev Project onedev |
|
Metrics |
cvssV3_1
|
Mon, 21 Oct 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 21 Oct 2024 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | OneDev is a Git server with CI/CD, kanban, and packages. A vulnerability in versions prior to 11.0.9 allows unauthenticated users to read arbitrary files accessible by the OneDev server process. This issue has been fixed in version 11.0.9. | |
Title | OneDev vulnerable to arbitrary file reading for unauthenticated user | |
Weaknesses | CWE-200 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-10-21T14:55:18.293Z
Updated: 2024-10-21T19:16:02.326Z
Reserved: 2024-08-26T18:25:35.444Z
Link: CVE-2024-45309
Vulnrichment
Updated: 2024-10-21T19:15:57.157Z
NVD
Status : Analyzed
Published: 2024-10-21T15:15:03.463
Modified: 2024-11-14T19:39:31.233
Link: CVE-2024-45309
Redhat
No data.