Arbitrary file read via crafted query (OD-2416)
Robin Shen opened 8 months ago

Any file owned by the user running OneDev server process can be read via a crafted query from UI.

  • OneDev commented 8 months ago

    State changed as code fixing the issue is committed (9b502651)

  • OneDev changed state to 'Closed' 8 months ago
    Previous Value Current Value
    Open
    Closed
  • OneDev commented 8 months ago

    State changed as build OD-6189 is successful

  • OneDev changed state to 'Released' 8 months ago
    Previous Value Current Value
    Closed
    Released
issue 1/1
Type
Security Vulnerability
Priority
Critical
Assignee
Labels
No labels
Issue Votes (0)
Watchers (3)
Reference
OD-2416
Please wait...
Connection lost or session expired, reload to recover
Page is in error, reload to recover