github.com
https://github.com/OctopusDeploy/Issues/issues/5042 CVE-2018-18850
HIGH
Octopus Deploy Authenticated Code Execution
Record summary
CVE-2018-18850 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
In Octopus Deploy 2018.8.0 through 2018.9.x before 2018.9.1, an authenticated user with permission to modify deployment processes could upload a maliciously crafted YAML configuration, potentially allowing for remote execution of arbitrary code, running in the same context as the Octopus Server (for self-hosted installations by default, SYSTEM).
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
MetasploitOctopus Deploy Authenticated Code ExecutionMetasploit exploitby James Otten <jamesotten1@gmail.com>Not analyzed1 file
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-18850