In affected versions of Octopus Server under certain conditions, a user with specific role assignments can access restricted project artifacts.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://advisories.octopus.com/post/2024/sa2024-05/ | vendor advisory |