Back to overview

CVE-2021-21244

CRITICAL
10.0
CVSS 3.1
Description
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, There is a vulnerability that enabled pre-auth server side template injection via Bean validation message tampering. Full details in the reference GHSA. This issue was fixed in 4.0.3 by disabling validation interpolation completely.

Metadata

CVE ID
CVE-2021-21244
State
PUBLISHED
Assigner
GitHub_M
Reserved
2020-12-22 00:00 UTC
Published
2021-01-15 20:05 UTC
Last updated
2024-08-03 18:09 UTC
Primary CWE
CWE-74
CWE-74 Improper Neutralization of Special Elements in Output…
Vendor / Product
theonedev / onedev
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Affected products (1)
VendorProductPlatformVersions
theonedev onedev < 4.0.3
Weakness (CWE)
CWESourceDescription
CWE-74 cna CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Back to overview