Improper access control in OneDev - CVE-2022-39208

 

Improper access control in OneDev - CVE-2022-39208

Published: September 13, 2022 / Updated: May 5, 2026


Vulnerability identifier: #VU129800
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-39208
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in the /opt/onedev/sites/ directory when handling requests for site files. A remote attacker can read exposed project files and repository data to disclose sensitive information.

Project IDs are incremental, which can facilitate enumeration of project data.


Affected software

OneDev

How to mitigate CVE-2022-39208

Install security update from vendor's website.

OneDev - update to 7.3.0

External References

Related Security Bulletins