PT-2018-16579 · Octopus Deploy · Octopus Deploy

Slewis74

·

Published

2018-01-03

·

Updated

2019-10-03

·

CVE-2018-4862

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Octopus Deploy versions 3.2.11 through 4.1.5
Description The issue allows an authenticated user with ProcessEdit permission to bypass scoping restrictions by referencing an Azure account in a specific way, potentially leading to an escalation of privileges.
Recommendations For versions 3.2.11 through 4.1.5, update to version 4.1.6 to resolve the issue.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-4862

Affected Products

Octopus Deploy