Skip to content

Arbitrary file reading for unauthenticated user

Critical
robinshine published GHSA-7wg5-6864-v489 Oct 19, 2024

Package

No package listed

Affected versions

<=11.0.8

Patched versions

11.0.9

Description

Impact

A criticial security vulnerability was found allowing unauthenticated user reading arbitrary file accessible by OneDev server process.

Patches

This issue has been fixed in 11.0.9

Severity

Critical

CVE ID

CVE-2024-45309

Weaknesses

No CWEs

Credits