First published: Tue Apr 30 2024(Updated: )
It was identified that in certain versions of Octopus Server, that a user created with no permissions could view all users, user roles and permissions. This functionality was removed in versions of Octopus Server after the fixed versions listed.
Credit: security@octopus.com
Affected Software | Affected Version | How to fix |
---|---|---|
Octopus Deploy | <= |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-4226 has a medium severity rating due to unauthorized access to user roles and permissions.
To fix CVE-2024-4226, upgrade to the latest version of Octopus Server where the vulnerability has been addressed.
CVE-2024-4226 affects certain earlier versions of Octopus Server prior to the fixed versions listed in the advisories.
Unauthorized users can access all users, user roles, and permissions in Octopus Server due to CVE-2024-4226.
No, CVE-2024-4226 was specifically confirmed in certain versions of Octopus Server prior to the release of the patch.