| |
Vulnerability CVE-2018-9039
Published: 2018-03-26 Modified: 2018-03-27
Description: |
In Octopus Deploy 2.0 and later before 2018.3.7, an authenticated user, with variable edit permissions, can scope some variables to targets greater than their permissions should allow. In other words, they can see machines beyond their team's scoped environments. |
Type:
CWE-269 (Improper Privilege Management)
CVSS2 => (AV:N/AC:L/Au:S/C:P/I:N/A:N)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
4/10 |
2.9/10 |
8/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Low |
Single time |
Confidentiality impact |
Integrity impact |
Availability impact |
Partial |
None |
None |
References: |
https://github.com/OctopusDeploy/Issues/issues/4407
https://octopus.com/downloads/compare?from=2018.3.6&to=2018.3.7
|
|
|
Copyright 2024, cxsecurity.com
|
|
|