CVE-2018-5706: High severity Octopus Octopus Deploy vulnerability
Published Jan 16, 2018
·Updated
An issue was discovered in Octopus Deploy before 4.1.9. Any user with user editing permissions can modify teams to give themselves Administer System permissions even if they didn't have them, as demonstrated by use of the RoleEdit or TeamEdit permission.
Affected Software
1 affected component
Octopus Octopus Deploy<4.1.9
Event History
Jan 16, 2018
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·10:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-5706?
CVE-2018-5706 is classified as a medium severity vulnerability.
2
How does CVE-2018-5706 affect Octopus Deploy?
CVE-2018-5706 allows any user with user editing permissions to elevate their privileges to Administer System.
3
What versions of Octopus Deploy are affected by CVE-2018-5706?
CVE-2018-5706 affects all versions of Octopus Deploy prior to 4.1.9.
4
How do I fix CVE-2018-5706?
To fix CVE-2018-5706, upgrade Octopus Deploy to version 4.1.9 or later.
5
What permissions are misconfigured in CVE-2018-5706?
CVE-2018-5706 involves misconfigured RoleEdit or TeamEdit permissions that allow unauthorized privilege escalation.