Vulnerability record · CVE-2021-21242 · published 15 January 2021
CVE-2021-21242: OneDev AttachmentUploadServlet deserialization allows pre-auth RCE
Onedev Project · Onedev
OneDev before 4.0.3 exposes AttachmentUploadServlet, which deserializes untrusted data from the Attachment-Support header without any authentication or authorization checks. Because the servlet is reachable pre-auth and the input is deserialized, an unauthenticated network attacker can achieve remote code execution. The flaw was fixed in 4.0.3 by removing the servlet and eliminating the deserialization path.
Description
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which can lead to pre-auth remote code execution. AttachmentUploadServlet deserializes untrusted data from the `Attachment-Support` header. This Servlet does not enforce any authentication or authorization checks. This issue may lead to pre-auth remote code execution. This issue was fixed in 4.0.3 by removing AttachmentUploadServlet and not using deserialization
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityPre-auth network-reachable remote code execution with a CVSS of 9.8 and very high EPSS makes this an urgent patch target.
What it is
OneDev before 4.0.3 exposes AttachmentUploadServlet, which deserializes untrusted data from the Attachment-Support header without any authentication or authorization checks. Because the servlet is reachable pre-auth and the input is deserialized, an unauthenticated network attacker can achieve remote code execution. The flaw was fixed in 4.0.3 by removing the servlet and eliminating the deserialization path.
Impact
An attacker gains remote code execution on the OneDev server without credentials, which can lead to full compromise of the host and any data or credentials it holds.
Attack surface
Reachable over the network via HTTP requests to AttachmentUploadServlet, with no authentication and no user interaction required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). The malicious payload is carried in the Attachment-Support header.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is very high (0.74191, 99.46th percentile), indicating strong likelihood of exploitation activity.
What to do
- Upgrade OneDev to 4.0.3 or later, which removes AttachmentUploadServlet and the deserialization path.
- If immediate upgrade is not possible, block or restrict network access to AttachmentUploadServlet at the reverse proxy or WAF.
- Do not expose the OneDev instance directly to the internet; place it behind authentication and network controls.
- After patching, review logs for prior requests to AttachmentUploadServlet and treat any as potential compromise.
- Rotate secrets and credentials stored or accessible on the OneDev host if exploitation is suspected.
Detection
- Search HTTP access logs for requests to AttachmentUploadServlet, especially with an Attachment-Support header.
- Alert on unexpected outbound connections or child processes spawned by the OneDev Java process.
- Monitor for anomalous file writes or new executables in OneDev application and temp directories.
- Review OneDev and host logs around the patch window for signs of prior exploitation attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/theonedev/onedev/commit/f864053176c08f59ef2d97fea192ceca46a4d9be | PatchThird Party Advisory |
| https://github.com/theonedev/onedev/security/advisories/GHSA-5q3q-f373-2jv8 | Third Party Advisory |
| https://github.com/theonedev/onedev/commit/f864053176c08f59ef2d97fea192ceca46a4d9be | PatchThird Party Advisory |
| https://github.com/theonedev/onedev/security/advisories/GHSA-5q3q-f373-2jv8 | Third Party Advisory |
Track CVE-2021-21242 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-21242), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.