Robin Shen
15 exploits
Active since Jan 2021
OneDev <= 15.0.6 - Authenticated Arbitrary File Overwrite via TarUtils.untar
OneDev Unauthenticated Arbitrary File Read
CVSS 7.5
OneDev < 4.0.3 - Unauthenticated Remote Code Execution via Attachment-Support Header Deserialization
CVSS 10.0
OneDev <4.0.3 - Pre-Auth Code Injection
CVSS 10.0
OneDev <4.0.3 - Server Side Template Injection
CVSS 10.0
OneDev < 4.0.3 - Arbitrary File Upload via AttachmentUploadServlet
CVSS 10.0
OneDev < 4.0.3 - Unauthenticated Sensitive Data Leak via UserResource Endpoint
CVSS 8.6
OneDev < 4.0.3 - Remote Code Execution via Build Endpoint Parameter Injection
CVSS 9.6
OneDev <4.4.1 - Blind LDAP Injection
CVSS 3.1
Onedev v7.4.14 - Path Traversal via Crafted JAR File Upload
CVSS 8.8
OneDev < 7.3.0 - Unauthenticated Remote Code Execution via Git Pre-Receive Callback Endpoint
CVSS 9.0
OneDev < 7.3.0 - Authenticated Remote Code Execution via Docker Socket Mount
CVSS 9.9
OneDev < 7.3.0 - Stored Cross-Site Scripting via Build Artifact HTML Rendering
CVSS 5.4
OneDev < 7.3.0 - Unauthenticated Arbitrary File Read via Project Directory Exposure
CVSS 7.5
Onedev <7.9.12 - Privilege Escalation
CVSS 8.1