CVE-2021-21244

10.0
CRITICALCVSS v3.1 Base Score
1.49%
LOW RiskEPSS (73rd percentile)

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, There is a vulnerability that enabled pre-auth server side template injection via Bean validation message tampering. Full details in the reference GHSA. This issue was fixed in 4.0.3 by disabling validation interpolation completely.

Published: 1/15/2021
Modified: 6/17/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

10CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

CVSS v2 Score

7.5

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Score (Exploitation Probability)

1.49%LOW Exploitation Risk
73rd percentile

This vulnerability has a 1.49% probability of being exploited in the next 30 days, ranking higher than 73% of all scored CVEs.

CWE Classification

Advertisement