ZeroHour

CVE-2024-4226

CVSS 3.1
3.5 low
EPSS
<1%p23
Published
()
Modified
Description

It was identified that in certain versions of Octopus Server, that a user created with no permissions could view all users, user roles and permissions. This functionality was removed in versions of Octopus Server after the fixed versions listed.

Vendors
octopus
Products
octopus server
Weakness
CWE-276
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.