onedev_project security advisories
7 threat alerts tracking vulnerabilities and security advisories that affect onedev_project products.
Vulnios monitors onedev_project CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent onedev_project security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2021-21243 — onedev_project — onedev
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, a Kubernetes REST endpoint exposes two methods that deserialize untrusted data from the request body. These endpoints do not en
criticalCVE-2021-21243Critical Vulnerability: CVE-2021-21249 — onedev_project — onedev
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is an issue involving YAML parsing which can lead to post-auth remote code execution. In order to parse and process YAML
criticalCVE-2021-21249Critical Vulnerability: CVE-2021-21248 — onedev_project — onedev
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability involving the build endpoint parameters. InputSpec is used to define parameters of a Build sp
criticalCVE-2021-21248Critical Vulnerability: CVE-2021-21244 — onedev_project — onedev
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, There is a vulnerability that enabled pre-auth server side template injection via Bean validation message tampering. Full detai
criticalCVE-2021-21244Critical Vulnerability: CVE-2021-21247 — onedev_project — onedev
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the application's BasePage registers an AJAX event listener (`AbstractPostAjaxBehavior`) in all pages other than the login page
criticalCVE-2021-21247Critical Vulnerability: CVE-2021-21242 — onedev_project — onedev
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which can lead to pre-auth remote code execution. AttachmentUploadServlet deserializes untrus
criticalCVE-2021-21242Critical Vulnerability: CVE-2021-21245 — onedev_project — onedev
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, AttachmentUploadServlet also saves user controlled data (`request.getInputStream()`) to a user specified location (`request.get
criticalCVE-2021-21245
Track onedev_project exposure across your environment
Vulnios automatically cross-references your asset inventory against new onedev_project CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan