In Octopus Deploy 2.0 and later before 2018.3.7, an authenticated user, with variable edit permissions, can scope some variables to targets greater than their permissions should allow. In other words, they can see machines beyond their team's scoped environments.
References
Link | Resource |
---|---|
https://github.com/OctopusDeploy/Issues/issues/4407 | Exploit Third Party Advisory |
https://octopus.com/downloads/compare?from=2018.3.6&to=2018.3.7 | Release Notes |
https://github.com/OctopusDeploy/Issues/issues/4407 | Exploit Third Party Advisory |
https://octopus.com/downloads/compare?from=2018.3.6&to=2018.3.7 | Release Notes |
Configurations
History
21 Nov 2024, 04:14
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/OctopusDeploy/Issues/issues/4407 - Exploit, Third Party Advisory | |
References | () https://octopus.com/downloads/compare?from=2018.3.6&to=2018.3.7 - Release Notes |
Information
Published : 2018-03-27 03:29
Updated : 2024-11-21 04:14
NVD link : CVE-2018-9039
Mitre link : CVE-2018-9039
CVE.ORG link : CVE-2018-9039
JSON object : View
Products Affected
octopus
- octopus_deploy
CWE
CWE-862
Missing Authorization