In Octopus Deploy 2.0 and later before 2018.3.7, an authenticated user, with variable edit permissions, can scope some variables to targets greater than their permissions should allow. In other words, they can see machines beyond their team's scoped environments.
References
Link | Resource |
---|---|
https://github.com/OctopusDeploy/Issues/issues/4407 | Exploit Third Party Advisory |
https://octopus.com/downloads/compare?from=2018.3.6&to=2018.3.7 | Release Notes |
Configurations
Information
Published : 2018-03-26 20:29
Updated : 2020-08-24 10:37
NVD link : CVE-2018-9039
Mitre link : CVE-2018-9039
JSON object : View
CWE
CWE-862
Missing Authorization
Products Affected
octopus
- octopus_deploy