Users able to edit build spec can execute arbitrary java code (OD-88)
Robin Shen opened 6 years ago

This is caused by using message template in hibernate validator. Details for the issue: https://securitylab.github.com/advisories/GHSL-2020-028-netflix-titus

  • OneDev changed state to 'Committed' 6 years ago
    Previous Value Current Value
    Open
    Committed
  • Robin Shen batch edited 6 years ago
    Name Previous Value Current Value
    State
    Committed
    Closed
issue 1/1
Type
Bug
Priority
Critical
Assignee
Affected Versions
Not Found
Iterations
Issue Votes (0)
Watchers (1)
Reference
OD-88
Please wait...
Connection lost or session expired, reload to recover
Page is in error, reload to recover