Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2024-45309EPSS 25% OneDev is a Git server with CI/CD, kanban, and packages. A vulnerability in versions prior to 11.0.9 allows unauthenticated users to read arbitrary f… Onedev 11.0.9+ Fix from $1,9502024-10-21 HIGH 8.8 CVE-2023-24828 Onedev is a self-hosted Git Server with CI/CD and Kanban. In versions prior to 7.9.12 the algorithm used to generate access token and password reset … Onedev 7.9.12+ Fix from $1,9502023-02-08 HIGH 8.8 CVE-2022-38301 Onedev v7.4.14 contains a path traversal vulnerability which allows attackers to access restricted files and directories via uploading a crafted JAR … Onedev Patch available Fix from $1,9502022-09-14 CRITICAL 9.9 CVE-2022-39206 Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. When using Docker-based job executors, the Docker socket (e.g. /var/run/docke… Onedev 7.3.0+ Fix from $2,3002022-09-13 CRITICAL 9.8 CVE-2022-39205 Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. In versions of Onedev prior to 7.3.0 unauthenticated users can take over a On… Onedev 7.3.0+ Fix from $2,3002022-09-13 HIGH 7.5 CVE-2022-39208 Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. All files in the /opt/onedev/sites/ directory are exposed and can be read by … Onedev 7.3.0+ Fix from $1,9502022-09-13 MEDIUM 5.4 CVE-2022-39207 Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. During CI/CD builds, it is possible to save build artifacts for later retriev… Onedev 7.3.0+ Fix from $1,6002022-09-13 CRITICAL 9.8 CVE-2021-21242EPSS 74% OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which can lead to pre-auth remote code exe… Onedev 4.0.3+ Fix from $2,3002021-01-15 CRITICAL 9.8 CVE-2021-21245 OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, AttachmentUploadServlet also saves user controlled data (`request.getInputSt… Onedev 4.0.3+ Fix from $2,3002021-01-15 HIGH 8.8 CVE-2021-21247 OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the application's BasePage registers an AJAX event listener (`AbstractPostAj… Onedev 4.0.3+ Fix from $1,9502021-01-15 HIGH 8.8 CVE-2021-21248 OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability involving the build endpoint parameters. I… Onedev 4.0.3+ Fix from $1,9502021-01-15 HIGH 8.8 CVE-2021-21249 OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is an issue involving YAML parsing which can lead to post-auth remote … Onedev 4.0.3+ Fix from $1,9502021-01-15 HIGH 8.8 CVE-2021-21251EPSS 13% OneDev is an all-in-one devops platform. In OneDev before version 4.0.3 there is a critical "zip slip" vulnerability. This issue may lead to arbitrar… Onedev 4.0.3+ Fix from $1,9502021-01-15 HIGH 7.5 CVE-2021-21246EPSS 49% OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the REST UserResource endpoint performs a security check to make sure that o… Onedev 4.0.3+ Fix from $1,9502021-01-15 MEDIUM 6.5 CVE-2021-21250 OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which may lead to arbitrary file read. Whe… Onedev 4.0.3+ Fix from $1,6002021-01-15 CRITICAL 9.8 CVE-2021-21243EPSS 54% OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, a Kubernetes REST endpoint exposes two methods that deserialize untrusted da… Onedev 4.0.3+ Fix from $2,3002021-01-15 CRITICAL 9.8 CVE-2021-21244 OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, There is a vulnerability that enabled pre-auth server side template injectio… Onedev 4.0.3+ Fix from $2,3002021-01-15