在受影响的 Octopus Server 版本中,拥有某些范围受限权限集的用户能够在 worker(包括 Octopus Server 内置 worker)上执行任意脚本。由于在脚本执行过程中权限验证存在缺陷,即使用户未获得相应的授权,脚本仍可能得以执行,从而导致权限检查失效,可能引发未授权执行的风险。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Octopus Deploy | Octopus Server | 2019.0.0 ~ 2026.1.11725 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet