Improper access control in OneDev - CVE-2022-39208
Published: September 13, 2022 / Updated: May 5, 2026
OneDev
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the /opt/onedev/sites/ directory when handling requests for site files. A remote attacker can read exposed project files and repository data to disclose sensitive information.
Project IDs are incremental, which can facilitate enumeration of project data.