PT-2017-11949 · Octopus Deploy · Octopus Deploy

Published

2017-07-17

·

Updated

2022-07-27

·

CVE-2017-11348

CVSS v2.0

6.3

Medium

VectorAV:N/AC:M/Au:S/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Octopus Deploy versions prior to 3.15.4
Description The issue allows an authenticated user with PackagePush permission to upload a maliciously crafted NuGet package. This could potentially lead to overwriting other packages or modifying system files due to a directory traversal vulnerability in the PackageId value.
Recommendations For versions prior to 3.15.4, update to version 3.15.4 or later to resolve the issue. As a temporary workaround, consider restricting the PackagePush permission to trusted users only until the update is applied.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-11348

Affected Products

Octopus Deploy