Pre-Auth SSTI via Bean validation message tampering
CVE-2021-21244

10CRITICAL

Key Information:

Vendor

Theonedev

Status
Vendor
CVE Published:
15 January 2021

What is CVE-2021-21244?

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, There is a vulnerability that enabled pre-auth server side template injection via Bean validation message tampering. Full details in the reference GHSA. This issue was fixed in 4.0.3 by disabling validation interpolation completely.

Affected Version(s)

onedev < 4.0.3

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.