ZeroHour

CVE-2017-15611

CVSS 3.0
6.5 medium
EPSS
<1%p52
Published
()
Modified
Description

In Octopus before 3.17.7, an authenticated user who was explicitly granted the permission to invite new users (aka UserInvite) can invite users to teams with escalated privileges.

Vendors
octopus
Products
octopus deploy
Weakness
CWE-732
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.