When Octopus Server is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL side-loading to gain privileged access.
2021-10-07T01:15:07.010
2024-11-21T05:56:27.703
Modified
CVSSv3.1: 7.8 (HIGH)
AV:L/AC:M/Au:N/C:P/I:P/A:P
3.4
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | octopus | octopus_deploy | < 2020.4.229 | Yes |
| Application | octopus | octopus_server | < 2020.5.256 | Yes |