在受影响的 Octopus Server 版本中,具有修改角色权限的已认证用户可以绕过防止访问滥用的保护措施,从而导致权限提升。攻击者可以削弱内置角色的权限,并将自己的账户添加到特权团队中。这一漏洞是由于对输入中的不安全等价性验证不当所致。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Octopus Deploy | Octopus Server | 2023.2.945< 2026.1.11768 |
affected |
2026.2.0< 2026.2.13408 |
affected | ||
2026.3.0< 2026.3.15816 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Octopus Deploy | Octopus Server | 2023.2.945 ~ 2026.1.11768 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet