← Vulnerability feed

Vulnerability record · CVE-2021-21242 · published 15 January 2021

CVE-2021-21242: OneDev AttachmentUploadServlet deserialization allows pre-auth RCE

Onedev Project · Onedev

OneDev before 4.0.3 exposes AttachmentUploadServlet, which deserializes untrusted data from the Attachment-Support header without any authentication or authorization checks. Because the servlet is reachable pre-auth and the input is deserialized, an unauthenticated network attacker can achieve remote code execution. The flaw was fixed in 4.0.3 by removing the servlet and eliminating the deserialization path.

9.8 CVSS 3.1 Critical EPSS 74% · top 0.5% CWE-74 · InjectionCWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score, v2 7.5
74%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which can lead to pre-auth remote code execution. AttachmentUploadServlet deserializes untrusted data from the `Attachment-Support` header. This Servlet does not enforce any authentication or authorization checks. This issue may lead to pre-auth remote code execution. This issue was fixed in 4.0.3 by removing AttachmentUploadServlet and not using deserialization

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityPre-auth network-reachable remote code execution with a CVSS of 9.8 and very high EPSS makes this an urgent patch target.

What it is

OneDev before 4.0.3 exposes AttachmentUploadServlet, which deserializes untrusted data from the Attachment-Support header without any authentication or authorization checks. Because the servlet is reachable pre-auth and the input is deserialized, an unauthenticated network attacker can achieve remote code execution. The flaw was fixed in 4.0.3 by removing the servlet and eliminating the deserialization path.

Impact

An attacker gains remote code execution on the OneDev server without credentials, which can lead to full compromise of the host and any data or credentials it holds.

Attack surface

Reachable over the network via HTTP requests to AttachmentUploadServlet, with no authentication and no user interaction required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). The malicious payload is carried in the Attachment-Support header.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is very high (0.74191, 99.46th percentile), indicating strong likelihood of exploitation activity.

What to do

  • Upgrade OneDev to 4.0.3 or later, which removes AttachmentUploadServlet and the deserialization path.
  • If immediate upgrade is not possible, block or restrict network access to AttachmentUploadServlet at the reverse proxy or WAF.
  • Do not expose the OneDev instance directly to the internet; place it behind authentication and network controls.
  • After patching, review logs for prior requests to AttachmentUploadServlet and treat any as potential compromise.
  • Rotate secrets and credentials stored or accessible on the OneDev host if exploitation is suspected.

Detection

  • Search HTTP access logs for requests to AttachmentUploadServlet, especially with an Attachment-Support header.
  • Alert on unexpected outbound connections or child processes spawned by the OneDev Java process.
  • Monitor for anomalous file writes or new executables in OneDev application and temp directories.
  • Review OneDev and host logs around the patch window for signs of prior exploitation attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-21242 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2022-39206Onedev project onedev vulnerabilityOnedev is an open source, self-hosted Git Server with CI/CD and Kanban. When using Docker-based job executors, the Docker socket (e.g. /var/run/docke…EPSS 2.1%9.8CVE-2022-39205Onedev project onedev improper authentication vulnerabilityOnedev is an open source, self-hosted Git Server with CI/CD and Kanban. In versions of Onedev prior to 7.3.0 unauthenticated users can take over a On…EPSS 2.4%9.8CVE-2021-21245Onedev project onedev unrestricted file upload vulnerabilityOneDev is an all-in-one devops platform. In OneDev before version 4.0.3, AttachmentUploadServlet also saves user controlled data (`request.getInputSt…EPSS 1.2%9.8CVE-2021-21243OneDev Kubernetes endpoint deserializes untrusted data pre-auth, enabling RCEOneDev before 4.0.3 exposes a Kubernetes REST endpoint with two methods that deserialize untrusted data from the request body. Those endpoints enforc…EPSS 54%analysed9.8CVE-2021-21244Onedev project onedev injection vulnerabilityOneDev is an all-in-one devops platform. In OneDev before version 4.0.3, There is a vulnerability that enabled pre-auth server side template injectio…EPSS 1.5%8.8CVE-2023-24828Onedev project onedev vulnerabilityOnedev is a self-hosted Git Server with CI/CD and Kanban. In versions prior to 7.9.12 the algorithm used to generate access token and password reset …EPSS 0.71%8.8CVE-2022-38301Onedev project onedev path traversal vulnerabilityOnedev v7.4.14 contains a path traversal vulnerability which allows attackers to access restricted files and directories via uploading a crafted JAR …EPSS 1.4%8.8CVE-2021-21247Onedev project onedev injection vulnerabilityOneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the application's BasePage registers an AJAX event listener (`AbstractPostAj…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2021-21242), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.