ZeroHour

CVE-2018-9039

PoC
CVSS 3.0
6.5 medium
EPSS
1%p61
Published
()
Modified
Description

In Octopus Deploy 2.0 and later before 2018.3.7, an authenticated user, with variable edit permissions, can scope some variables to targets greater than their permissions should allow. In other words, they can see machines beyond their team's scoped environments.

Vendors
octopus
Products
octopus deploy
Weakness
CWE-862
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.