← Back

CVE-2017-11348

nvd nist
Published: Jul 17, 2017Modified: May 13, 2026

JSON object

Loading...
5.7
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
Exploitability: 2.1 / Impact: 3.6
Source: NVD

Description

In Octopus Deploy 3.x before 3.15.4, an authenticated user with PackagePush permission to upload packages could upload a maliciously crafted NuGet package, potentially overwriting other packages or modifying system files. This is a directory traversal in the PackageId value.

Affected (192)

2 products
Octopus Deploy
Octopus Server
Configuration A
192 vulnerable
Vulnerable SoftwareAffected Versions
Octopus
Version 3.6.0
Version 3.7.0
Octopus
Version 3.0.0
Version 3.0.10
Version 3.0.11
Version 3.0.12
Version 3.0.13
Version 3.0.14
Version 3.0.15
Version 3.0.16
Version 3.0.17
Version 3.0.18
Version 3.0.19
Version 3.0.1
Version 3.0.20
Version 3.0.21
Version 3.0.22
Version 3.0.23
Version 3.0.24
Version 3.0.25
Version 3.0.26
Version 3.0.2
Version 3.0.3
Version 3.0.4
Version 3.0.5
Version 3.0.6
Version 3.0.7
Version 3.0.8
Version 3.0.9
Version 3.1.0
Version 3.1.0 beta0001
Version 3.1.0 beta0002
Version 3.1.12
Version 3.1.13
Version 3.1.1
Version 3.1.2
Version 3.1.3
Version 3.1.4
Version 3.1.5
Version 3.1.6
Version 3.1.7
Version 3.10.0
Version 3.10.1
Version 3.11.0
Version 3.11.10
Version 3.11.11
Version 3.11.12
Version 3.11.13
Version 3.11.14
Version 3.11.15
Version 3.11.16
Version 3.11.17
Version 3.11.18
Version 3.11.1
Version 3.11.2
Version 3.11.3
Version 3.11.4
Version 3.11.5
Version 3.11.6
Version 3.11.7
Version 3.11.9
Version 3.12.0
Version 3.12.1
Version 3.12.2
Version 3.12.3
Version 3.12.4
Version 3.12.5
Version 3.12.6
Version 3.12.7
Version 3.12.9
Version 3.13.0
Version 3.13.10
Version 3.13.1
Version 3.13.2
Version 3.13.3
Version 3.13.5
Version 3.13.6
Version 3.13.7
Version 3.13.9
Version 3.14.15926
Version 3.14.1592
Version 3.14.159
Version 3.14.15
Version 3.14.1
Version 3.15.0
Version 3.15.1
Version 3.15.2
Version 3.15.3
Version 3.2.0
Version 3.2.0 beta0001
Version 3.2.10
Version 3.2.11
Version 3.2.15
Version 3.2.16
Version 3.2.17
Version 3.2.19
Version 3.2.1
Version 3.2.20
Version 3.2.21
Version 3.2.22
Version 3.2.23
Version 3.2.24
Version 3.2.2
Version 3.2.3
Version 3.2.4
Version 3.2.6
Version 3.2.7
Version 3.2.8
Version 3.2.9
Version 3.3.0
Version 3.3.0 beta0001
Version 3.3.0 beta0002
Version 3.3.10
Version 3.3.11
Version 3.3.12
Version 3.3.14
Version 3.3.15
Version 3.3.16
Version 3.3.17
Version 3.3.18
Version 3.3.19
Version 3.3.1
Version 3.3.20
Version 3.3.21
Version 3.3.22
Version 3.3.24
Version 3.3.25
Version 3.3.26
Version 3.3.27
Version 3.3.2
Version 3.3.3
Version 3.3.4
Version 3.3.5
Version 3.3.6
Version 3.3.8
Version 3.3.9
Version 3.4.0
Version 3.4.0 beta0001
Version 3.4.0 beta0002
Version 3.4.10
Version 3.4.11
Version 3.4.12
Version 3.4.13
Version 3.4.14
Version 3.4.15
Version 3.4.1
Version 3.4.3
Version 3.4.4
Version 3.4.5
Version 3.4.6
Version 3.4.7
Version 3.4.8
Version 3.4.9
Version 3.5.1
Version 3.5.2
Version 3.5.4
Version 3.5.5
Version 3.5.6
Version 3.5.7
Version 3.5.8
Version 3.5.9
Version 3.6.1
Version 3.6.2
Version 3.7.10
Version 3.7.11
Version 3.7.12
Version 3.7.13
Version 3.7.14
Version 3.7.15
Version 3.7.16
Version 3.7.17
Version 3.7.18
Version 3.7.1
Version 3.7.2
Version 3.7.3
Version 3.7.4
Version 3.7.5
Version 3.7.6
Version 3.7.7
Version 3.7.8
Version 3.7.9
Version 3.8.0
Version 3.8.1
Version 3.8.2
Version 3.8.3
Version 3.8.4
Version 3.8.5
Version 3.8.6
Version 3.8.7
Version 3.8.8
Version 3.8.9
Version 3.9.0

References (2)

Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.