CVE-2020-10678: High severity octopus deploy vulnerability
Published Mar 19, 2020
·Updated
In Octopus Deploy before 2020.1.5, for customers running on-premises Active Directory linked to their Octopus server, an authenticated user can leverage a bug to escalate privileges.
Affected Software
1 affected component
Octopus Octopus Deploy<2020.1.5
Event History
Mar 19, 2020
CVE Published
via MITRE·02:31 PM
Data Sourced
via MITRE·02:31 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-10678?
The severity of CVE-2020-10678 is high.
2
What is the description of CVE-2020-10678?
CVE-2020-10678 allows an authenticated user to escalate privileges on Octopus Deploy before version 2020.1.5.
3
How can an authenticated user exploit CVE-2020-10678?
An authenticated user can exploit CVE-2020-10678 by leveraging a bug to escalate privileges.
4
Which version of Octopus Deploy is affected by CVE-2020-10678?
Octopus Deploy versions before 2020.1.5 are affected by CVE-2020-10678.
5
Is there a reference for CVE-2020-10678?
Yes, you can find a reference for CVE-2020-10678 at the following link: [https://github.com/OctopusDeploy/Issues/issues/6258](https://github.com/OctopusDeploy/Issues/issues/6258)