← Back to CVE List

CVE-2021-21242

Published: 2021-01-15T21:15Z
Last Modified: 2024-11-21T05:47Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which can lead to pre-auth remote code execution. AttachmentUploadServlet deserializes untrusted data from the `Attachment-Support` header. This Servlet does not enforce any authentication or authorization checks. This issue may lead to pre-auth remote code execution. This issue was fixed in 4.0.3 by removing AttachmentUploadServlet and not using deserialization > MITRE Terms of Use apply – see LICENSE‑MITRE.txt