CVE-2024-45309: Onedev Project Onedev
High severity, CVSS 7.5. EPSS: 24.5% chance of exploitation in the next 30 days.
OneDev is a Git server with CI/CD, kanban, and packages. A vulnerability in versions prior to 11.0.9 allows unauthenticated users to read arbitrary files accessible by the OneDev server process. This issue has been fixed in version 11.0.9.
Affected products
- Onedev Project Onedev: before 11.0.9 (fixed in 11.0.9)
Published 2024-10-21. Last modified 2026-06-17.