CVE-2021-21246 is a sensitive data leak vulnerability affecting OneDev versions prior to 4.0.3, an all-in-one DevOps platform. An unauthenticated attacker can retrieve arbitrary user details, including access tokens, via an unauthenticated REST endpoint. This vulnerability carries a CVSS score of 7.5 (High) due to its network-based attack vector, low complexity, and high impact on confidentiality, potentially leading to impersonation of any user, including administrators. While there is no evidence of active exploitation or Metasploit modules, a Nuclei template exists, and there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.0.3CPE matchmatch criteria | cpe:2.3:a:onedev_project:onedev:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.