Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2g53-8j24-x4mg

Опубликовано: 06 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 6.3

Описание

A vulnerability was determined in theonedev onedev up to 15.0.5. This affects an unknown part of the file /repositories/{projectId}/default-branch of the component REST API. This manipulation of the argument project.defaultBranch causes improper authorization. It is possible to initiate the attack remotely. Upgrading to version 15.0.6 is able to mitigate this issue. Upgrading the affected component is advised.

A vulnerability was determined in theonedev onedev up to 15.0.5. This affects an unknown part of the file /repositories/{projectId}/default-branch of the component REST API. This manipulation of the argument project.defaultBranch causes improper authorization. It is possible to initiate the attack remotely. Upgrading to version 15.0.6 is able to mitigate this issue. Upgrading the affected component is advised.

EPSS

Процентиль: 12%
0.00214
Низкий

5.3 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-266

Связанные уязвимости

CVSS3: 6.3
nvd
около 2 месяцев назад

A vulnerability was determined in theonedev onedev up to 15.0.5. This affects an unknown part of the file /repositories/{projectId}/default-branch of the component REST API. This manipulation of the argument project.defaultBranch causes improper authorization. It is possible to initiate the attack remotely. Upgrading to version 15.0.6 is able to mitigate this issue. Upgrading the affected component is advised.

EPSS

Процентиль: 12%
0.00214
Низкий

5.3 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-266