OneDev is a Git server with CI/CD, kanban, and packages. A vulnerability in versions prior to 11.0.9 allows unauthenticated users to read arbitrary files accessible by the OneDev server process. This issue has been fixed in version 11.0.9.
Metrics
Affected Vendors & Products
References
History
Thu, 14 Nov 2024 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Onedev Project
Onedev Project onedev |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:onedev_project:onedev:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Onedev Project
Onedev Project onedev |
|
| Metrics |
cvssV3_1
|
Mon, 21 Oct 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 21 Oct 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OneDev is a Git server with CI/CD, kanban, and packages. A vulnerability in versions prior to 11.0.9 allows unauthenticated users to read arbitrary files accessible by the OneDev server process. This issue has been fixed in version 11.0.9. | |
| Title | OneDev vulnerable to arbitrary file reading for unauthenticated user | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-10-21T14:55:18.293Z
Updated: 2024-10-21T19:16:02.326Z
Reserved: 2024-08-26T18:25:35.444Z
Link: CVE-2024-45309
Updated: 2024-10-21T19:15:57.157Z
Status : Analyzed
Published: 2024-10-21T15:15:03.463
Modified: 2024-11-14T19:39:31.233
Link: CVE-2024-45309
No data.