Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

theonedev — Vulnerabilities & Security Advisories 23

Browse all 23 CVE security advisories affecting theonedev. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Theonedev develops software tools primarily used for development and deployment automation. Historically, their products have been vulnerable to multiple remote code execution flaws, cross-site scripting vulnerabilities, and privilege escalation issues, accounting for the majority of their 17 recorded CVEs. Security researchers have identified consistent patterns in input validation and access control weaknesses across their codebase. While no major public security incidents have been widely documented, the accumulation of CVEs suggests ongoing challenges in secure coding practices. Their tools remain popular despite these vulnerabilities, indicating a trade-off between functionality and security that continues to concern security professionals.

Top products by theonedev: onedev
CVE ID Title CVSS Severity Published
CVE-2026-49248 OneDev: RCE through absolute-path symlink following allows low-privileged users to overwrite arbitrary server via TarUtils.untar — onedev CWE-61 - - 2026-06-18
CVE-2026-11441 theonedev Pull Request issues canAccessIssue improper authorization — onedev CWE-285 6.3 Medium 2026-06-06
CVE-2026-11440 theonedev REST API default-branch improper authorization — onedev CWE-285 6.3 Medium 2026-06-06
CVE-2026-11439 theonedev Parent Project projects improper authorization — onedev CWE-285 6.3 Medium 2026-06-06
CVE-2026-11438 theonedev projects improper authorization — onedev CWE-285 6.3 Medium 2026-06-06
CVE-2026-44647 OneDev: Path Traversal (read capability via Git LFS pointer resolution) — onedev CWE-22 - - 2026-05-14
CVE-2024-45309 OneDev vulnerable to arbitrary file reading for unauthenticated user — onedev CWE-200 7.5AI High AI 2024-10-21
CVE-2023-24828 Use of Cryptographically Weak Pseudo-Random Number Generator in Onedev — onedev CWE-338 8.1 High 2023-02-07
CVE-2022-39206 CI/CD Docker Escape in OneDev — onedev CWE-610 9.9 Critical 2022-09-13
CVE-2022-39207 Persistent XSS in OneDev — onedev CWE-79 5.4 Medium 2022-09-13
CVE-2022-39208 Git Repository Disclosure in Onedev — onedev CWE-552 7.5 High 2022-09-13
CVE-2022-39205 Access Control Bypass in Onedev — onedev CWE-287 9.0 Critical 2022-09-13
CVE-2021-32651 LDAP injection via OneDev may leak some LDAP directory information — onedev CWE-90 3.1 Low 2021-06-01
CVE-2021-21245 Pre-Auth Arbitrary File Upload — onedev CWE-434 10.0 Critical 2021-01-15
CVE-2021-21246 Pre-Auth Access token leak — onedev CWE-862 8.6 High 2021-01-15
CVE-2021-21247 Post-Auth Unsafe Deserialization on BasePage (AJAX) — onedev CWE-74 9.6 Critical 2021-01-15
CVE-2021-21249 Post-Auth Unsafe Yaml deserialization — onedev CWE-74 9.6 Critical 2021-01-15
CVE-2021-21248 Post-Auth Arbitrary Code execution via Groovy script injection — onedev CWE-74 9.6 Critical 2021-01-15
CVE-2021-21250 Post-Auth External Entity Expansion (XXE) — onedev CWE-538 7.7 High 2021-01-15
CVE-2021-21251 ZipSlip Arbitrary File Upload — onedev CWE-22 7.7 High 2021-01-15
CVE-2021-21242 Pre-Auth Unsafe Deserialization on AttachmentUploadServet — onedev CWE-74 10.0 Critical 2021-01-15
CVE-2021-21243 Pre-Auth Unsafe Deserialization on KubernetesResource — onedev CWE-74 10.0 Critical 2021-01-15
CVE-2021-21244 Pre-Auth SSTI via Bean validation message tampering — onedev CWE-74 10.0 Critical 2021-01-15

This page lists every published CVE security advisory associated with theonedev. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.