CVE-2020-12286
28.04.2020, 07:15
In Octopus Deploy before 2019.12.9 and 2020 before 2020.1.12, the TaskView permission is not scoped to any dimension. For example, a scoped user who is scoped to only one tenant can view server tasks scoped to any other tenant.Enginsight
Vendor | Product | Version |
---|---|---|
octopus | octopus_deploy | 𝑥 < 2019.12.9 |
octopus | octopus_deploy | 2020.1 ≤ 𝑥 < 2020.1.12 |
𝑥
= Vulnerable software versions
References