Description
An issue was discovered in Octopus before 3.17.7. When the special Guest user account is granted the CertificateExportPrivateKey permission, and Guest Access is enabled for the Octopus Server, an attacker can sign in as the Guest account and export Certificates managed by Octopus, including the private key.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-7062 | An issue was discovered in Octopus before 3.17.7. When the special Guest user account is granted the CertificateExportPrivateKey permission, and Guest Access is enabled for the Octopus Server, an attacker can sign in as the Guest account and export Certificates managed by Octopus, including the private key. |
References
| Link | Providers |
|---|---|
| https://github.com/OctopusDeploy/Issues/issues/3869 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T19:57:27.410Z
Reserved: 2017-10-19T00:00:00.000Z
Link: CVE-2017-15610
No data.
Status : Modified
Published: 2017-10-19T08:29:00.810
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-15610
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD