Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

onedev — Vulnerabilities & Security Advisories 23

All 23 CVE vulnerabilities found in onedev, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumeration vulnerabilities associated with the onedev product, categorized by vendor and weakness type. It serves as a centralized resource for security researchers and developers to analyze the historical security posture of this specific continuous integration and development platform. The content aggregates publicly disclosed security advisories, bug reports, and vulnerability entries that have been recorded for onedev. The collection covers a broad time range, spanning from the early releases of the software up to the most recent patches and updates. This ensures a comprehensive view of how the product has evolved in response to discovered security flaws over several years. By consolidating these scattered data points, the page provides a clear timeline of remediation efforts and recurring issue patterns. Users can utilize this aggregation to track how the vendor handles security disclosures and responds to critical findings. It allows for a deeper understanding of specific weakness classes prevalent in the codebase, helping teams prioritize fixes based on historical frequency and severity. Additionally, individuals can look up the complete vulnerability history of onedev to assess the stability and security maturity of different versions. This holistic approach supports informed decision-making regarding upgrades, risk assessments, and compliance auditing, ensuring that stakeholders have access to accurate and contextualized security data without needing to search through multiple disparate sources.

Vendor: theonedev

CVE ID Title CVSS Severity Published
CVE-2026-49248 OneDev: RCE through absolute-path symlink following allows low-privileged users to overwrite arbitrary server via TarUtils.untar CWE-61 - - 2026-06-18
CVE-2026-11441 theonedev Pull Request issues canAccessIssue improper authorization CWE-285 6.3 Medium 2026-06-06
CVE-2026-11440 theonedev REST API default-branch improper authorization CWE-285 6.3 Medium 2026-06-06
CVE-2026-11439 theonedev Parent Project projects improper authorization CWE-285 6.3 Medium 2026-06-06
CVE-2026-11438 theonedev projects improper authorization CWE-285 6.3 Medium 2026-06-06
CVE-2026-44647 OneDev: Path Traversal (read capability via Git LFS pointer resolution) CWE-22 - - 2026-05-14
CVE-2024-45309 OneDev vulnerable to arbitrary file reading for unauthenticated user CWE-200 7.5AI High AI 2024-10-21
CVE-2023-24828 Use of Cryptographically Weak Pseudo-Random Number Generator in Onedev CWE-338 8.1 High 2023-02-07
CVE-2022-39206 CI/CD Docker Escape in OneDev CWE-610 9.9 Critical 2022-09-13
CVE-2022-39207 Persistent XSS in OneDev CWE-79 5.4 Medium 2022-09-13
CVE-2022-39208 Git Repository Disclosure in Onedev CWE-552 7.5 High 2022-09-13
CVE-2022-39205 Access Control Bypass in Onedev CWE-287 9.0 Critical 2022-09-13
CVE-2021-32651 LDAP injection via OneDev may leak some LDAP directory information CWE-90 3.1 Low 2021-06-01
CVE-2021-21245 Pre-Auth Arbitrary File Upload CWE-434 10.0 Critical 2021-01-15
CVE-2021-21246 Pre-Auth Access token leak CWE-862 8.6 High 2021-01-15
CVE-2021-21247 Post-Auth Unsafe Deserialization on BasePage (AJAX) CWE-74 9.6 Critical 2021-01-15
CVE-2021-21249 Post-Auth Unsafe Yaml deserialization CWE-74 9.6 Critical 2021-01-15
CVE-2021-21248 Post-Auth Arbitrary Code execution via Groovy script injection CWE-74 9.6 Critical 2021-01-15
CVE-2021-21250 Post-Auth External Entity Expansion (XXE) CWE-538 7.7 High 2021-01-15
CVE-2021-21251 ZipSlip Arbitrary File Upload CWE-22 7.7 High 2021-01-15
CVE-2021-21242 Pre-Auth Unsafe Deserialization on AttachmentUploadServet CWE-74 10.0 Critical 2021-01-15
CVE-2021-21243 Pre-Auth Unsafe Deserialization on KubernetesResource CWE-74 10.0 Critical 2021-01-15
CVE-2021-21244 Pre-Auth SSTI via Bean validation message tampering CWE-74 10.0 Critical 2021-01-15

All 23 known CVE vulnerabilities affecting onedev with full Chinese analysis, references, and POCs where available.