First published: Mon Apr 30 2018(Updated: )
In Octopus Deploy before 2018.4.7, target and tenant tag variable scopes were not checked against the list of tenants the user has access to.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Octopus Deploy | <2018.4.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10550 has a medium severity rating, as it can lead to unauthorized access to tenant-specific variable scopes.
To fix CVE-2018-10550, upgrade Octopus Deploy to version 2018.4.7 or later.
CVE-2018-10550 affects all versions of Octopus Deploy prior to 2018.4.7.
CVE-2018-10550 is an access control vulnerability related to tenant tag variable scopes.
Users of Octopus Deploy before version 2018.4.7 who manage tenant tag variable scopes may be impacted by CVE-2018-10550.