Web: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-39208

Sept. 13, 2022, 7:15 p.m. |

National Vulnerability Database nist.gov

Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. All files in the /opt/onedev/sites/ directory are exposed and can be read by unauthenticated users. This directory contains all projects, including their bare git repos and build artifacts. This file disclosure vulnerability can be used by unauthenticated attackers to leak all project files of any project. Since project IDs are incremental, an attacker could iterate through them and leak all project data. This issue has been resolved in …

cve

Cybersecurity Engineer

@ Apercen Partners LLC | Folsom, CA

IDM Sr. Security Developer

@ The Ohio State University | Columbus, OH, United States

IT Security Engineer

@ Stylitics | New York City

Information Security Engineer

@ VDA Labs | Remote

Information Security Analyst

@ Metropolitan Transportation Commission | San Francisco, CA

Personnel Security Specialist I

@ NT Concepts | Remote

Cyber Security Manager (SOC/Threat Detection)

@ Nubank | São Paulo

Personnel Security Specialist II

@ NT Concepts | Remote

Infrastructure Consultant - Graduate

@ Netcompany | Leeds, United Kingdom

Senior Cloud Network Security Engineer with expertise in WIFI technologies

@ Uni Systems | Luxembourg, Luxembourg, Luxembourg

DevSecOps Engineer - TOP SECRET Clearance Required - Colorado Springs/Denver/Pueblo

@ Spry Squared, Inc. | Colorado Springs, CO, United States

Product Security Associate

@ Mekari | Jakarta, Jakarta, Indonesia