Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w4vm-8m9w-5qwm

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

An issue was discovered in Octopus Deploy 3.4. A deployment target can be configured with an Account or Certificate that is outside the scope of the deployment target. An authorised user can potentially use a certificate that they are not in scope to use. An authorised user is also able to obtain certificate metadata by associating a certificate with certain resources that should fail scope validation.

An issue was discovered in Octopus Deploy 3.4. A deployment target can be configured with an Account or Certificate that is outside the scope of the deployment target. An authorised user can potentially use a certificate that they are not in scope to use. An authorised user is also able to obtain certificate metadata by associating a certificate with certain resources that should fail scope validation.

EPSS

Процентиль: 32%
0.00124
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 4.3
nvd
больше 5 лет назад

An issue was discovered in Octopus Deploy 3.4. A deployment target can be configured with an Account or Certificate that is outside the scope of the deployment target. An authorised user can potentially use a certificate that they are not in scope to use. An authorised user is also able to obtain certificate metadata by associating a certificate with certain resources that should fail scope validation.

EPSS

Процентиль: 32%
0.00124
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-295