First published: Tue Jan 16 2018(Updated: )
An issue was discovered in Octopus Deploy before 4.1.9. Any user with user editing permissions can modify teams to give themselves Administer System permissions even if they didn't have them, as demonstrated by use of the RoleEdit or TeamEdit permission.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Octopus Deploy | <4.1.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-5706 is classified as a medium severity vulnerability.
CVE-2018-5706 allows any user with user editing permissions to elevate their privileges to Administer System.
CVE-2018-5706 affects all versions of Octopus Deploy prior to 4.1.9.
To fix CVE-2018-5706, upgrade Octopus Deploy to version 4.1.9 or later.
CVE-2018-5706 involves misconfigured RoleEdit or TeamEdit permissions that allow unauthorized privilege escalation.