← Back to browse · API

CVE-2021-21244

Severity
CRITICAL
CVSS
10.0
EPSS
0.01494
Risk score
40.52
CISA KEV
No
PoC
No
Published
2021-01-15
Modified
2024-08-03
First seen
2026-08-08
Aliases
EUVD-2021-8627
Products
theonedev:onedev < 4.0.3
Sources
euvd EUVD-2021-8627

Description

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, There is a vulnerability that enabled pre-auth server side template injection via Bean validation message tampering. Full details in the reference GHSA. This issue was fixed in 4.0.3 by disabling validation interpolation completely.

References