Security Advisory

CVE-2021-21243

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-01-15 20:05:21
Last updated 2024-08-03 18:09:15
Assigner GitHub_M
State PUBLISHED

Description

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, a Kubernetes REST endpoint exposes two methods that deserialize untrusted data from the request body. These endpoints do not enforce any authentication or authorization checks. This issue may lead to pre-auth RCE. This issue was fixed in 4.0.3 by not using deserialization at KubernetesResource side.