OneDev before version 4.0.3 contains an insecure endpoint that allows retrieval of arbitrary user details, including access tokens, due to missing security checks on /users/{id}, letting attackers leak sensitive data and impersonate users, exploit requires no special conditions.
id: CVE-2021-21246
info:
name: OneDev < 4.0.3 - User Access Token Leak
author: DhiyaneshDk
se
...