First published: Thu Mar 19 2020(Updated: )
In Octopus Deploy before 2020.1.5, for customers running on-premises Active Directory linked to their Octopus server, an authenticated user can leverage a bug to escalate privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Octopus Octopus Deploy | <2020.1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-10678 is high.
CVE-2020-10678 allows an authenticated user to escalate privileges on Octopus Deploy before version 2020.1.5.
An authenticated user can exploit CVE-2020-10678 by leveraging a bug to escalate privileges.
Octopus Deploy versions before 2020.1.5 are affected by CVE-2020-10678.
Yes, you can find a reference for CVE-2020-10678 at the following link: [https://github.com/OctopusDeploy/Issues/issues/6258](https://github.com/OctopusDeploy/Issues/issues/6258)