It was identified that in certain versions of Octopus Server, that a user created with no permissions could view all users, user roles and permissions. This functionality was removed in versions of Octopus Server after the fixed versions listed.
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-04-30 02:15
Updated : 2024-12-04 18:15
NVD link : CVE-2024-4226
Mitre link : CVE-2024-4226
CVE.ORG link : CVE-2024-4226
JSON object : View
Products Affected
No product.
CWE
CWE-276
Incorrect Default Permissions