CVE-2017-15611
—CVSS 3.0
6.5 medium
EPSS
<1%p52
Published
()
Modified
Description
In Octopus before 3.17.7, an authenticated user who was explicitly granted the permission to invite new users (aka UserInvite) can invite users to teams with escalated privileges.
- Vendors
- octopus
- Products
- octopus deploy
- Weakness
- CWE-732
- Vector
- CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.