← Back to CVE List

CVE-2018-5706

Published: 2018-01-16T10:29Z
Last Modified: 2024-11-21T04:09Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An issue was discovered in Octopus Deploy before 4.1.9. Any user with user editing permissions can modify teams to give themselves Administer System permissions even if they didn't have them, as demonstrated by use of the RoleEdit or TeamEdit permission. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt