ZeroHour

CVE-2024-45309

large

Unauthenticated Arbitrary File Read in OneDev Git/CI-CD Server

CVSS 4.0
8.7 high
EPSS
25%p98
Published
()
Modified
AI analysis

OneDev, a self-hosted Git server with integrated CI/CD, kanban boards, and package registries, is vulnerable in versions prior to 11.0.9 to a flaw that allows unauthenticated users to read arbitrary files accessible to the OneDev server process (CWE-200 and CWE-22 indicate a path-handling/path traversal weakness resulting in information disclosure). Because the flaw is reachable over the network with no privileges and no user interaction required (CVSS 4.0: AV:N/PR:N/UI:N), any attacker who can reach the OneDev service can trigger it without an account and gain read access to files the process can access, potentially including configuration files, credentials, tokens, SSH keys, and source code; the high confidentiality impact (VC:H) drives the 8.7 (high) severity score. All OneDev deployments running versions before 11.0.9 are affected, whether exposed to the internet or reachable by untrusted users on internal networks. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, but the high EPSS score of 24.5% (98th percentile) signals a significant probability of exploitation within the next 30 days.

What to do: Upgrade all OneDev servers to version 11.0.9 or later. Because exploitation requires no authentication, restrict network access to the OneDev service (firewall rules or reverse-proxy allowlists) until patched, and check service logs for unauthenticated file-read activity. If compromise is suspected, rotate credentials, tokens, and secrets readable by the OneDev process.

Affected
onedev project onedevall versions prior to 11.0.9 (fixed in 11.0.9)
Estimated exposure
large≈10,000–100,000 total self-hosted installations, of which likely only a few thousand are internet-exposed — OneDev is a niche self-hosted alternative to GitLab/Gitea that is typically deployed inside corporate networks or as personal servers; public internet scans have generally shown only a low thousands of exposed instances, implying a larger…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

OneDev is a Git server with CI/CD, kanban, and packages. A vulnerability in versions prior to 11.0.9 allows unauthenticated users to read arbitrary files accessible by the OneDev server process. This issue has been fixed in version 11.0.9.

Vendors
onedev project
Products
onedev
Weakness
CWE-200, CWE-22
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.