CVE-2017-11348 - CERT CVE
ID CVE-2017-11348
Sažetak In Octopus Deploy 3.x before 3.15.4, an authenticated user with PackagePush permission to upload packages could upload a maliciously crafted NuGet package, potentially overwriting other packages or modifying system files. This is a directory traversal in the PackageId value.
Reference
CVSS
Base: 6.3
Impact: 6.9
Exploitability:6.8
Pristup
VektorSloženostAutentikacija
NETWORK MEDIUM SINGLE
Impact
PovjerljivostCjelovitostDostupnost
NONE COMPLETE NONE
CVSS vektor AV:N/AC:M/Au:S/C:N/I:C/A:N
Zadnje važnije ažuriranje 27-07-2022 - 15:36
Objavljeno 17-07-2017 - 13:18