Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-24828

Опубликовано: 08 фев. 2023
Источник: nvd
CVSS3: 8.1
CVSS3: 8.8
EPSS Низкий

Описание

Onedev is a self-hosted Git Server with CI/CD and Kanban. In versions prior to 7.9.12 the algorithm used to generate access token and password reset keys was not cryptographically secure. Existing normal users (or everyone if it allows self-registration) may exploit this to elevate privilege to obtain administrator permission. This issue is has been addressed in version 7.9.12. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:onedev_project:onedev:*:*:*:*:*:*:*:*
Версия до 7.9.12 (исключая)

EPSS

Процентиль: 31%
0.0012
Низкий

8.1 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-338

EPSS

Процентиль: 31%
0.0012
Низкий

8.1 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-338