OneDev is a Git server with CI/CD, kanban, and packages. A vulnerability in versions prior to 11.0.9 allows unauthenticated users to read arbitrary files accessible by the OneDev server process. This issue has been fixed in version 11.0.9.
History

Thu, 14 Nov 2024 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Onedev Project
Onedev Project onedev
Weaknesses CWE-22
CPEs cpe:2.3:a:onedev_project:onedev:*:*:*:*:*:*:*:*
Vendors & Products Onedev Project
Onedev Project onedev
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Mon, 21 Oct 2024 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Oct 2024 15:00:00 +0000

Type Values Removed Values Added
Description OneDev is a Git server with CI/CD, kanban, and packages. A vulnerability in versions prior to 11.0.9 allows unauthenticated users to read arbitrary files accessible by the OneDev server process. This issue has been fixed in version 11.0.9.
Title OneDev vulnerable to arbitrary file reading for unauthenticated user
Weaknesses CWE-200
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-10-21T14:55:18.293Z

Updated: 2024-10-21T19:16:02.326Z

Reserved: 2024-08-26T18:25:35.444Z

Link: CVE-2024-45309

cve-icon Vulnrichment

Updated: 2024-10-21T19:15:57.157Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-21T15:15:03.463

Modified: 2024-11-14T19:39:31.233

Link: CVE-2024-45309

cve-icon Redhat

No data.