← Back to CVE List

CVE-2017-17665

Published: 2017-12-13T20:29Z
Last Modified: 2024-11-21T03:18Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In Octopus Deploy before 4.1.3, the machine update process doesn't check that the user has access to all environments. This allows an access-control bypass because the set of environments to which a machine is scoped may include environments in which the user lacks access. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt