Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9wjw-f37c-vj83

Опубликовано: 15 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.2

Описание

In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts on a worker (including the Octopus Server built-in worker). Incorrect permission validation during script execution would allow the script to execute without the user possessing the required authorisation.

In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts on a worker (including the Octopus Server built-in worker). Incorrect permission validation during script execution would allow the script to execute without the user possessing the required authorisation.

EPSS

Процентиль: 18%
0.00257
Низкий

7.2 High

CVSS4

Дефекты

CWE-863

Связанные уязвимости

nvd
4 дня назад

In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts on a worker (including the Octopus Server built-in worker). Incorrect permission validation during script execution would allow the script to execute without the user possessing the required authorisation.

EPSS

Процентиль: 18%
0.00257
Низкий

7.2 High

CVSS4

Дефекты

CWE-863