Lucene search

K
cvelistGitHub_MCVELIST:CVE-2021-21244
HistoryJan 15, 2021 - 8:05 p.m.

CVE-2021-21244 Pre-Auth SSTI via Bean validation message tampering

2021-01-1520:05:13
CWE-74
GitHub_M
www.cve.org
2
cve-2021-21244
pre-auth
ssti
bean validation
onedev
vulnerability
server side
template injection
message tampering
ghsa
fixed issue
validation interpolation.

CVSS3

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

AI Score

9.7

Confidence

High

EPSS

0.003

Percentile

70.2%

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, There is a vulnerability that enabled pre-auth server side template injection via Bean validation message tampering. Full details in the reference GHSA. This issue was fixed in 4.0.3 by disabling validation interpolation completely.

CNA Affected

[
  {
    "product": "onedev",
    "vendor": "theonedev",
    "versions": [
      {
        "status": "affected",
        "version": "< 4.0.3"
      }
    ]
  }
]

CVSS3

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

AI Score

9.7

Confidence

High

EPSS

0.003

Percentile

70.2%

Related for CVELIST:CVE-2021-21244