CVE-2024-4811: Low severity octopus deploy vulnerability
Published Jul 25, 2024
·Updated
In affected versions of Octopus Server under certain conditions, a user with specific role assignments can access restricted project artifacts.
Affected Software
6 affected components
Octopus Deploy Octopus Server
All of the following
Any of the following
Octopus Octopus Server>=2023.1.4189<2023.4.8608
Octopus Octopus Server>=2024.1.437<2024.1.12759
Octopus Octopus Server>=2024.2.101<2024.2.9193
Any of the following
Linux Linux kernel
Microsoft Windows
Event History
Jul 25, 2024
CVE Published
via MITRE·04:46 AM
Data Sourced
via MITRE·04:46 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-4811?
CVE-2024-4811 has been classified with a moderate severity level due to unauthorized access potential.
2
How do I fix CVE-2024-4811?
To fix CVE-2024-4811, ensure that role assignments are properly configured to restrict access to project artifacts.
3
What versions of Octopus Server are affected by CVE-2024-4811?
CVE-2024-4811 affects specific versions of Octopus Server where certain role conditions are met.
4
Can CVE-2024-4811 lead to data breaches?
Yes, CVE-2024-4811 can potentially lead to data breaches if project artifacts are accessed by unauthorized users.
5
What should I do if I suspect my Octopus Server is affected by CVE-2024-4811?
If you suspect your Octopus Server is affected by CVE-2024-4811, review your role assignments and consider applying the recommended fixes immediately.