Path traversal in OneDev - CVE-2021-21251
Published: January 12, 2021 / Updated: May 5, 2026
OneDev
OneDev
Description
The vulnerability allows a remote user to overwrite arbitrary files.
The vulnerability exists due to path traversal in TarUtils untar processing within the KubernetesResource upload-outcomes REST endpoint when extracting user-controlled tar archive data from the request body. A remote user can send a specially crafted tar archive to overwrite arbitrary files.
Exploitation requires a valid JobToken.