Vulnerability Description
In Octopus Deploy before 2019.12.9 and 2020 before 2020.1.12, the TaskView permission is not scoped to any dimension. For example, a scoped user who is scoped to only one tenant can view server tasks scoped to any other tenant.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Octopus | Octopus Deploy | < 2019.12.9 |
References
- https://github.com/OctopusDeploy/Issues/issues/6331Third Party Advisory
- https://github.com/OctopusDeploy/Issues/issues/6332Third Party Advisory
- https://github.com/OctopusDeploy/Issues/issues/6333Third Party Advisory
- https://github.com/OctopusDeploy/Issues/issues/6331Third Party Advisory
- https://github.com/OctopusDeploy/Issues/issues/6332Third Party Advisory
- https://github.com/OctopusDeploy/Issues/issues/6333Third Party Advisory
FAQ
What is CVE-2020-12286?
CVE-2020-12286 is a vulnerability with a CVSS score of 4.3 (MEDIUM). In Octopus Deploy before 2019.12.9 and 2020 before 2020.1.12, the TaskView permission is not scoped to any dimension. For example, a scoped user who is scoped to only one tenant can view server tasks ...
How severe is CVE-2020-12286?
CVE-2020-12286 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-12286?
Check the references section above for vendor advisories and patch information. Affected products include: Octopus Octopus Deploy.