PT-2021-14354 · Onedev · Onedev

·

CVE-2021-21244

·

Published

2021-01-15

·

Updated

2022-10-19

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: OneDev versions prior to 4.0.3
Description: The issue is related to a pre-auth server side template injection via Bean validation message tampering in OneDev, an all-in-one devops platform. This was fixed in version 4.0.3 by disabling validation interpolation completely.
Recommendations: For versions prior to 4.0.3, update to version 4.0.3 or later to resolve the issue by having validation interpolation disabled. As a temporary workaround, consider disabling validation interpolation completely until the update can be applied.

Fix

Code Injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-21244
GHSA-VM26-XG39-CFJ4

Affected Products

Onedev