Vulnerability record · CVE-2021-21243 · published 15 January 2021
CVE-2021-21243: OneDev Kubernetes endpoint deserializes untrusted data pre-auth, enabling RCE
Onedev Project · Onedev
OneDev before 4.0.3 exposes a Kubernetes REST endpoint with two methods that deserialize untrusted data from the request body. Those endpoints enforce no authentication or authorization, so the flaw can lead to pre-auth remote code execution. It was fixed in 4.0.3 by removing deserialization on the KubernetesResource side.
Description
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, a Kubernetes REST endpoint exposes two methods that deserialize untrusted data from the request body. These endpoints do not enforce any authentication or authorization checks. This issue may lead to pre-auth RCE. This issue was fixed in 4.0.3 by not using deserialization at KubernetesResource side.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required and a pre-auth RCE outcome, plus very high EPSS, makes this an urgent patch.
What it is
OneDev before 4.0.3 exposes a Kubernetes REST endpoint with two methods that deserialize untrusted data from the request body. Those endpoints enforce no authentication or authorization, so the flaw can lead to pre-auth remote code execution. It was fixed in 4.0.3 by removing deserialization on the KubernetesResource side.
Impact
An unauthenticated attacker can execute arbitrary code on the OneDev server, gaining full control of the host and any data or credentials it holds.
Attack surface
Reachable over the network via the Kubernetes REST endpoint; the CVSS vector shows no privileges and no user interaction required, and the description confirms no authentication or authorization checks.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged, but EPSS is 0.54494 (99th percentile), indicating a high modeled likelihood of exploitation.
What to do
- Upgrade OneDev to 4.0.3 or later, which removes deserialization on the KubernetesResource side.
- If immediate upgrade is not possible, block or restrict network access to the Kubernetes REST endpoint at the reverse proxy or firewall.
- Require authentication and authorization in front of the endpoint until patched.
- Audit the OneDev host for signs of compromise and rotate any secrets or credentials it stores.
Detection
- Monitor OneDev access logs for requests to Kubernetes REST endpoint paths, especially from unexpected source IPs.
- Alert on deserialization or Java gadget-related errors and stack traces in OneDev logs.
- Watch for unexpected child processes spawned by the OneDev service (shells, curl, wget).
- Baseline normal OneDev API traffic and flag anomalous POST bodies to the Kubernetes endpoint.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/theonedev/onedev/commit/9637fc8fa461c5777282a0021c3deb1e7a48f137 | PatchThird Party Advisory |
| https://github.com/theonedev/onedev/security/advisories/GHSA-9mmq-fm8c-q4fv | Third Party Advisory |
| https://github.com/theonedev/onedev/commit/9637fc8fa461c5777282a0021c3deb1e7a48f137 | PatchThird Party Advisory |
| https://github.com/theonedev/onedev/security/advisories/GHSA-9mmq-fm8c-q4fv | Third Party Advisory |
Track CVE-2021-21243 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-21243), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.