Deserialization of Untrusted Data in OneDev - CVE-2021-21249
Published: January 12, 2021 / Updated: May 5, 2026
OneDev
OneDev
Description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to unsafe deserialization in the BuildSpec YAML parser when processing a crafted YAML BuildSpec file. A remote user can supply a specially crafted YAML payload to execute arbitrary code.
The issue is post-authentication.