Security Advisory

CVE-2024-45309

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-10-21 14:55:18
Last updated 2024-10-21 19:16:02
Assigner GitHub_M
State PUBLISHED

Description

OneDev is a Git server with CI/CD, kanban, and packages. A vulnerability in versions prior to 11.0.9 allows unauthenticated users to read arbitrary files accessible by the OneDev server process. This issue has been fixed in version 11.0.9.