CVE-2018-18850: Critical severity octopus deploy vulnerability
In Octopus Deploy 2018.8.0 through 2018.9.x before 2018.9.1, an authenticated user with permission to modify deployment processes could upload a maliciously crafted YAML configuration, potentially allowing for remote execution of arbitrary code, running in the same context as the Octopus Server (for self-hosted installations by default, SYSTEM).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18850?
CVE-2018-18850 is considered a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2018-18850?
To fix CVE-2018-18850, update Octopus Deploy to version 2018.9.1 or later.
Who is affected by CVE-2018-18850?
CVE-2018-18850 affects authenticated users of Octopus Deploy versions 2018.8.0 to 2018.9.0.
What actions can an attacker perform with CVE-2018-18850?
An attacker can upload a malicious YAML configuration that allows for the execution of arbitrary code.
Is access control relevant in CVE-2018-18850?
Yes, an authenticated user with permission to modify deployment processes can exploit CVE-2018-18850.