PT-2017-14130 · Octopus · Octopus

Nick Josevski

·

Published

2017-10-19

·

Updated

2019-10-03

·

CVE-2017-15611

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Octopus versions prior to 3.17.7
Description The issue allows an authenticated user with the permission to invite new users to invite users to teams with escalated privileges.
Recommendations For versions prior to 3.17.7, update to version 3.17.7 or later to resolve the issue.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-15611

Affected Products

Octopus