CVE-2018-10550

HIGH

Octopus Deploy <2018.4.7 - Info Disclosure

Title source: llm
STIX 2.1

Description

In Octopus Deploy before 2018.4.7, target and tenant tag variable scopes were not checked against the list of tenants the user has access to.

References (1)

Core 1
Core References
Issue Tracking, Third Party Advisory x_refsource_confirm
https://github.com/OctopusDeploy/Issues/issues/4454

Scores

CVSS v3 7.5
EPSS 0.0127
EPSS Percentile 66.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-269
Status published
Products (1)
octopus/octopus_deploy < 2018.4.7
Published Apr 30, 2018
Tracked Since Feb 18, 2026