OneDev
cpe:2.3:a:onedev_project:onedev:*:*:*:*:*:*:*
- < 15.0.2
A path traversal vulnerability has been identified in OneDev Git server versions prior to 15.0.2. This issue arises from a breakdown in the expected separation between repository-managed Git Large File Storage (LFS) metadata and server-specific filesystem paths. As a result, a repository object can manipulate raw blob reads to access arbitrary local files that the server account can reach. Users with push permissions to any repository can exploit this vulnerability to read any server files accessible by the server process.
Exploitation of this vulnerability allows unauthorized access to server files through Git LFS pointer resolution, bypassing normal repository boundaries.
Users can upgrade to OneDev version 15.0.2 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.