Code Injection in OneDev - CVE-2021-21248
Published: January 12, 2021 / Updated: May 5, 2026
OneDev
OneDev
Description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to code injection in InputSpec when processing user-controlled build parameters. A remote user can inject arbitrary Groovy code to execute arbitrary code.
Exploitation requires the ability to control job parameters in a build specification.