Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-21245

Опубликовано: 15 янв. 2021
Источник: nvd
CVSS3: 10
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, AttachmentUploadServlet also saves user controlled data (request.getInputStream()) to a user specified location (request.getHeader("File-Name")). This issue may lead to arbitrary file upload which can be used to upload a WebShell to OneDev server. This issue is addressed in 4.0.3 by only allowing uploaded file to be in attachments folder. The webshell issue is not possible as OneDev never executes files in attachments folder.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:onedev_project:onedev:*:*:*:*:*:*:*:*
Версия до 4.0.3 (исключая)

EPSS

Процентиль: 57%
0.00345
Низкий

10 Critical

CVSS3

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-434

EPSS

Процентиль: 57%
0.00345
Низкий

10 Critical

CVSS3

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-434