CVE-2017-15611
medium
CVSS v3
6.5
CVSS v2
4.0
VIR risk
6.5
Description
In Octopus before 3.17.7, an authenticated user who was explicitly granted the permission to invite new users (aka UserInvite) can invite users to teams with escalated privileges.
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — https://github.com/OctopusDeploy/Issues/issues/3864
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| octopus | octopus_deploy | {"endIncluding":"3.17.6"} | |
References
CWEs
CWE-732
Verify integrity in audit chain (admin only). AS-IS.