CVE-2017-17665: High severity Octopus Octopus Deploy vulnerability
Published Dec 13, 2017
·Updated
In Octopus Deploy before 4.1.3, the machine update process doesn't check that the user has access to all environments. This allows an access-control bypass because the set of environments to which a machine is scoped may include environments in which the user lacks access.
Affected Software
1 affected component
Octopus Octopus Deploy<4.1.3
Event History
Dec 13, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-17665?
The severity of CVE-2017-17665 is rated as high with a score of 8.8.
2
How do I fix CVE-2017-17665?
To fix CVE-2017-17665, upgrade Octopus Deploy to version 4.1.3 or later.
3
What does CVE-2017-17665 allow an attacker to do?
CVE-2017-17665 allows an attacker to bypass access controls by updating machines in environments where they lack permissions.
4
Which versions of Octopus Deploy are affected by CVE-2017-17665?
CVE-2017-17665 affects all versions of Octopus Deploy prior to 4.1.3.
5
What type of vulnerability is CVE-2017-17665 classified as?
CVE-2017-17665 is classified as an access-control bypass vulnerability.