CVE-2020-12286

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/04/2020
Last modified:
21/07/2021

Description

In Octopus Deploy before 2019.12.9 and 2020 before 2020.1.12, the TaskView permission is not scoped to any dimension. For example, a scoped user who is scoped to only one tenant can view server tasks scoped to any other tenant.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:octopus:octopus_deploy:*:*:*:*:*:*:*:* 2019.12.9 (excluding)
cpe:2.3:a:octopus:octopus_deploy:*:*:*:*:*:*:*:* 2020.1 (including) 2020.1.12 (excluding)